> For the complete index of the 402pay docs, see [llms.txt](https://developer.402pay.co/llms.txt).

# Frequently asked questions

What businesses ask most about 402pay, grouped by payments, webhooks, wallet, keys and billing.

- [Payments and checkout](https://developer.402pay.co/faq.md#payments-and-checkout): What customers can pay with, and what happens when they pay the wrong amount. 8 questions
- [Webhooks](https://developer.402pay.co/faq.md#webhooks): Deliveries that don't arrive, retries, and testing your handler. 4 questions
- [Wallet](https://developer.402pay.co/faq.md#wallet): Custody, deposits, and connecting a wallet you already use. 5 questions
- [Keys and security](https://developer.402pay.co/faq.md#keys-and-security): Signing in, passwords, API keys, and what to do when one leaks. 8 questions
- [Billing](https://developer.402pay.co/faq.md#billing): Rates, flat fees, your fee statement and how fees are collected. 4 questions

Looking up an error? See [troubleshooting](https://developer.402pay.co/troubleshooting.md). Not sure what a term means? See the [glossary](https://developer.402pay.co/glossary.md).

## Payments and checkout

### What is 402pay?

402pay is a payment processing platform for businesses that want to accept cards and crypto through one checkout, without handing custody of their revenue to a third party.

Your team shares hosted checkouts or creates payments from your own systems through the API. Customers pay by card, Apple Pay, Google Pay or crypto, and every payment lands directly in a self-custody wallet your business controls.

There are no balances to withdraw, payout schedules or reserves: funds are yours as soon as the network confirms them.

### Do we need to write code?

No. Create a payment link in the dashboard and share it anywhere. When you're ready to integrate, the [API and signed webhooks](https://developer.402pay.co/index.md) let you create payments from your own systems, and test keys let you rehearse every outcome before you go live.

### Which assets and networks are supported?

USDC, USDT, Bitcoin, Ether and Solana, across Polygon, Ethereum, Solana, Tron and Bitcoin. You decide which ones checkout offers. See [supported networks](https://developer.402pay.co/guides/networks.md).

### Can customers pay by card?

Yes. Enable cards in Settings and send customers to the payment or payment-link URL. Hosted checkout shows the available methods and opens a secure page for card details, the final total and any required identity checks.

Your deposit arrives in a supported coin and network. Read the payment's settlement details and fulfill the order after verifying `payment.succeeded`. Checkout handles unsuccessful attempts and offers another try when available.

### What if a customer sends the wrong amount?

A transfer short by no more than your underpayment tolerance, 0.5% unless you change it, counts as paid in full. Less than that makes the payment `underpaid`: checkout asks the customer for the rest, and you can request it later or accept what arrived. More than the amount due lands in your wallet in full, and `payment.overpaid` tells you the excess. See [underpayments and overpayments](https://developer.402pay.co/guides/underpayments.md).

### Can a customer pay after the checkout expires?

A transfer that arrives after the quote expired still reaches your wallet, but the rate no longer holds, so the payment becomes `needs_review`. Accept it as it is, or send the funds back. See [needs review](https://developer.402pay.co/guides/underpayments.md#needs-review).

### How are refunds and disputes handled?

Refunds stay under your control: you send them from your wallet, in the asset and amount you choose, for card and crypto payments alike. There's no refund endpoint, since money never moves on an API key. See [refunds, returns and disputes](https://developer.402pay.co/guides/refunds.md).

Cardholders can still dispute a card payment with their bank. You'll be asked for evidence, and a clear description of what customers are buying, with your refund policy shown at checkout, keeps disputes rare.

### Does 402pay email our customers?

No. Every paid payment has a hosted [receipt](https://developer.402pay.co/guides/receipts.md) the customer sees after paying. Link to it, or send your own confirmation when your webhook hears the payment succeeded.

## Webhooks

### Why didn't a webhook arrive?

Every attempt is recorded with its signed request and your server's answer, which you can read in the dashboard under Developers, then Webhooks. Check that the endpoint is turned on, subscribes to the event type and answers over HTTPS. A local 402pay records deliveries without sending them. See [troubleshooting webhooks](https://developer.402pay.co/guides/webhooks.md#troubleshooting).

### How long are failed deliveries retried?

A delivery gets 8 attempts in all, spread over about 28 hours and starting 5 seconds after the first one fails. After the last, resend it from the dashboard or with `POST /webhook-deliveries/{id}/resend`.

### Can we get events we missed?

Yes. [`GET /events`](https://developer.402pay.co/api/events/list.md) lists every event with a snapshot of its subject, whether or not a webhook delivered it, and any delivery can be resent.

### How do we test our handler?

Send a test event from the dashboard or with `POST /webhooks/{id}/test`. It's signed like any delivery, with `test: true` and a made-up subject whose `data` holds only its `id`, so skip it before you fulfill anything.

## Wallet

### Do you hold our funds?

No. 402pay is non-custodial. Payments land in a wallet whose keys only your business holds, so we can't move, freeze or reverse your funds.

### How quickly do payments reach our wallet?

As fast as the network allows. A crypto payment is in your wallet once it has the confirmations its network needs, typically seconds on Polygon or Solana and minutes on Bitcoin. Card payments follow the same network confirmations after the payment reaches its destination.

### Can we use a wallet we already have?

Yes. Connect it as an external wallet by its public keys: an xpub or zpub, or one fixed address, for each network family. Networks you leave out aren't offered at checkout, and sends happen in that wallet's own app. See [wallet and deposits](https://developer.402pay.co/guides/settlement.md).

### Can the API move money out of our wallet?

No. An API key can read balances and transactions, but sends happen only in the dashboard, signed in your browser with your encryption password. An external wallet sends from its own app.

### What if we lose our recovery phrase or encryption password?

402pay can't recover either one: the phrase is encrypted in your browser, and only the encrypted copy is stored. Back both up somewhere safe and offline before you take real payments.

## Keys and security

### How is our account secured?

Your team signs in with a passkey, or with an email and a password, confirmed by a code we email, plus optional two-step verification, and sees a list of every active session. We email you about new sign-ins, passkeys added or removed, and changes to your email, password or two-step verification. API keys can be limited to exactly what each integration needs, every webhook is signed, and your wallet's recovery phrase is encrypted in your browser before anything reaches us.

### What if I forget my password?

Use Forgot password on the sign-in page. We email a link that works once, for 30 minutes. If two-step verification is on, you'll also need a code from your app or a recovery code. Resetting signs out every device. If you've lost those too, contact us at [support@402pay.co](mailto:support@402pay.co).

### What if the confirmation code doesn't arrive?

Check your spam folder. A minute after the last code, you can ask for a new one on the same page. Each code works for 15 minutes, and a sign-up waits a day to be confirmed. If you closed the page, sign in with the same email and password in the same browser to pick up where you left off, or open the link in the email.

### Why does the dashboard ask for my password again?

Some changes decide where payments go or who can reach your business: adding or deleting the wallet, changing its encryption password, creating API keys or webhooks, changing a webhook's URL, adding or removing a passkey and deleting a business. If you haven't signed in or confirmed it's you in the last 15 minutes, the dashboard asks first: use a passkey, or your password and, when two-step verification is on, a code. We also email you whenever the wallet changes.

### Can we limit what an API key can do?

Yes. A restricted key gets none, read or write on each resource: `GET` needs read and every other method needs write. Give each integration only what it uses. See [restricted keys](https://developer.402pay.co/authentication.md#restricted-keys).

### What should we do if a secret key leaks?

Create a new key in the dashboard under Developers, then API keys, deploy it, then revoke the old one, which stops working at once. Only a hash of each secret is stored, so a lost secret can't be shown again either. See [security best practices](https://developer.402pay.co/guides/security.md).

### What happens after too many wrong two-step codes?

Five wrong codes in a row lock that person's codes for 15 minutes, counted across every sign-in, so starting over doesn't help. Wait for the lock to end, then use a code from your authenticator or one of your recovery codes.

### What happens after too many wrong passwords?

Five failed sign-ins in a row lock that email for a minute, and each further five lock it for longer, up to an hour. A browser you've signed in with before keeps its own count, so someone guessing from elsewhere can't lock you out of it. After 100 in a row from other browsers, the password stops working in them until it's reset, and we email the account. Signing in successfully or resetting the password clears the count.

## Billing

### What does it cost?

An intro rate of 0% per crypto payment and 3% per card payment. On top of that, $0.25 per successful payment, and $5 a month for a self-custody wallet or $15 a month for an external one. There's no setup fee. See [pricing](https://402pay.co/pricing) for every add-on.

### Does anything come out of a payment?

No. Every payment, by card or crypto, lands in your wallet whole. Its rate, in `reporting.fee`, and the $0.25 per transaction, in `reporting.transaction_fee`, go on your fee statement with the wallet's monthly fee. `reporting.net` is what you keep once they're paid.

### How do I pay the fees on my statement?

You don't have to do anything. Once you owe $25.00, 402pay sends some of your payments to its own address instead of your wallet, whole, until what you owe is paid. Your customers pay as usual, and those payments show as collected as fees. An overpayment becomes credit for future fees. See [fees and billing](https://developer.402pay.co/guides/fees.md).

### Can my customers pay the fees?

Yes. Under Settings, Payments, choose who pays 402pay's fees. When your customers do, checkout adds the rate for their method and the $0.25 flat fee to their total, worked out on your price, so you keep the whole price. Each payment shows it in `customer_fee`, and an API payment can choose for itself with `fee_payer`. See [passing fees on](https://developer.402pay.co/guides/reconciliation.md#passing-fees-on).
