> For the complete index of the 402pay docs, see [llms.txt](https://developer.402pay.co/llms.txt).

# Wallet and deposits

The three kinds of wallet, how each payment lands in yours, and who holds the keys.

Every business has one wallet, and its payments land straight in it, apart from those that pay your fees. 402pay never holds your funds, so there's no balance to withdraw and no payout to wait for. Set it up in the dashboard, under Wallet: create a new one, import one, or connect a wallet you already use.

## Three kinds of wallet

| source | What it is | Where you send from |
| --- | --- | --- |
| `created` | A new wallet whose recovery phrase is made in your browser. | The dashboard, signed in your browser. |
| `imported` | A wallet from another app, brought in with its 12 or 24-word recovery phrase. | The dashboard, signed in your browser. |
| `external` | A wallet that keeps its own keys, such as a hardware wallet. You share only public keys or addresses. | Your wallet app. Record each send in the dashboard by its transaction hash. |

- A business has exactly one wallet. Creating another returns 409 `wallet_exists`.
- [`GET /wallet`](https://developer.402pay.co/api/wallet/retrieve.md) returns its `source`, balances and main addresses.
- A created or imported wallet is $5 a month, and an external one $15. See [pricing](https://402pay.co/pricing).

## How payments land

- A crypto payment lands at its checkout's address, in the coin and network the customer paid in.
- A card payment lands in an enabled coin and network your wallet can receive. Checkout selects a compatible route before reserving the destination.
- Each deposit is an `in` wallet transaction with the `payment_id` it came from and the whole amount that arrived, since fees never come out of it. The deposit, in the payment's `settlement` field, names the address and transaction.
- Balances are per coin and network, adding up every address. Sends draw on whichever of the wallet's addresses hold the coin, largest first.
- While you owe 402pay fees, some payments go to its address instead, to pay them. Their `settlement.destination` is `fees` and they add nothing to your wallet. See [fees and billing](https://developer.402pay.co/guides/fees.md).

## Addresses

A wallet derives its addresses from public keys, so 402pay can hand out new ones without being able to spend from them.

- Index 0 on each network is the main address, the one Receive shows. Every checkout reserves the next unused index, so each transfer matches exactly one payment.
- Polygon and Ethereum share one set of addresses and count indexes together, so an address never serves two payments on any of them.

## Solana addresses

Every Solana checkout pays to a fresh address as well. Solana's usual key derivation needs the recovery phrase for each new address, so when you create or import a wallet, your browser also shares a Solana checkout key: a public key that derives a new address for every checkout, the way an EVM account's extended public key does. Only the recovery phrase makes the keys that spend from these addresses, so 402pay can't move the funds.

Index 0 is the main address, the one Receive shows and Solana wallet apps find from your phrase. Checkout addresses sit on a branch of their own that wallet apps don't scan, so move their funds with Send in the dashboard, which signs for them in your browser, or with only your recovery phrase on the [Solana recovery page](https://dash.402pay.co/recover/solana). `address_counts.solana` on `GET /wallet` counts the Solana indexes handed out. The [Solana checkout addresses](https://developer.402pay.co/guides/solana-checkout-addresses.md) guide publishes the derivation.

## External wallets

An external wallet shares only what receiving needs. Networks you leave out aren't offered at checkout.

| Networks | Share |
| --- | --- |
| Polygon, Ethereum | An account's extended public key, `xpub…`, or one `0x` address. One covers both networks. |
| Bitcoin | An `xpub…` or `zpub…`, or one address. |
| Solana | One address. |
| Tron | One address. |

- With an extended public key, every checkout gets its own address. With a single address, every checkout on those networks pays that same address, so two customers paying at once can't be told apart by address. Share an extended public key wherever your wallet exports one.
- Extended private keys are refused.
- To take cards, connect a wallet that can receive a coin and network supported by an available card route.
- Sends happen in your wallet app. Record each one in the dashboard with its transaction hash, so your wallet's history here matches. A real-chain send stays pending with no effect on balances until the network verifies the sender, recipient, coin and amount against that hash. Its USD value remains zero while unverified; its fee stays zero because no fee amount is verified. An unrelated transfer cannot confirm it. Simulated external hash records fail after the pending timer because there is no chain evidence to verify.

## Your keys

> A created or imported wallet's recovery phrase never reaches 402pay. It's encrypted in your browser with an encryption password only you know, and only the encrypted copy is stored. That password is all that protects the copy, so the dashboard refuses one that's easy to guess, such as a common password, a word or name, a date, a keyboard pattern or your business's name. Sends and anything else that needs the phrase unlock it in your browser. An external wallet has no phrase here at all.

> 402pay can't recover a lost recovery phrase or encryption password. Back both up before you take real payments.

Money never moves on an API key. A key can read balances and transactions, and add notes, but sends are made or recorded only in the dashboard.

## Deleting a wallet

Once your business has received a payment (one collected as fees, or a referral payout, counts too), [deleting its wallet](https://developer.402pay.co/api/wallet/delete.md) takes effect 24 hours after you ask. The wallet keeps receiving payments until then, so someone who got into your account can't swap in a wallet of their own before you see the email. The email has a link that cancels the deletion without signing in, and the Wallet page shows it with a Cancel deletion button. A business still being set up loses its wallet right away, and changing the encryption password is never held.

## Next steps

- [Reporting and reconciliation](https://developer.402pay.co/guides/reconciliation.md): Which amounts to report, how payments match your wallet, and how to export a period.
- [Refunds, returns and disputes](https://developer.402pay.co/guides/refunds.md): Send refunds from your wallet, return funds you don't accept, and keep disputes rare.
- [Supported networks](https://developer.402pay.co/guides/networks.md): Every coin and network checkout accepts, and the confirmations each one needs.
- [Security best practices](https://developer.402pay.co/guides/security.md): Narrow keys, rotations without downtime, a locked-down webhook endpoint and a secure account.
