payments, deposits and bank_funding. Delivery, signatures and retries are on Webhooks; isolation and base URLs are on Environments.
GET /v2/partners/config returns the machine-readable catalog under capabilities.webhooks, with eventGroups, a recommendedEvents subset and the delivery policy. Subscribe by group rather than by name, and ignore an unknown event name safely instead of throwing, because names are added over time.
Act on each payment event
Every event is a prompt. ReadGET /v2/payments/{paymentId} and act on what it returns.
Act on deposit and bank funding events
deposit.* covers value arriving at a reusable deposit address. bank_funding.* covers value arriving through a virtual account; its payload carries the account, the facility, the transaction and the amounts, never bank details.
The intermediate deposit states are not delivered to partner endpoints. If you need finer progress than detected, settled, reversed and requires_intervention, poll
GET /v2/accounts/{accountId}/deposits instead.Rehearse every case in sandbox
Sandbox runs the same state machine and the same verification as production, against test networks. Have these in place first:- A sandbox app credential, and the sandbox base URL.
- An endpoint that verifies signatures over the raw body, with delivery logs you can read.
- An account with an active settlement destination on a chain you will accept.
GET /v2/partners/configread from sandbox, rather than a list copied from a page.
Run each case against the state your production code will actually be in. A case that passes because someone was watching the database is not a pass.
A sandbox pass proves your code, not a live rail
- Chain ids differ. Sandbox runs test networks. An address or asset valid in one environment is not valid in the other, and a chain id must never be carried across.
- Capabilities do not carry. A capability proven in sandbox stays off in production until it is granted there. Read config with the production credential before you assume otherwise.
- Accounts do not migrate. Your first production call for a customer is a create.
- Some corridors have no sandbox behind them. Where a rail has no provider sandbox, the first production transfer is also the first real test of that corridor. Plan a supervised low-value transfer rather than a launch.
- Virtual account issuance is certified on sandbox rather than proven in production. See On-ramp accounts.
GET /v2/partners/config at startup.
Next: Webhooks
Signature verification, dedupe headers and retry behaviour.