API Reference
The TridiPay API lets you create crypto deposit requests, request payouts, query balances and receive signed webhooks. All amounts are decimal strings in the currency of the asset.
https://tridipay.com/api/v1
Authentication
Authenticate every request with your API key. Write requests must also be signed.
| X-TridiPay-Key | Your public API key. |
| X-TridiPay-Timestamp | Unix timestamp (seconds) of the request. |
| X-TridiPay-Signature | HMAC-SHA256 signature of the request. |
Request signing
The signature is computed over the timestamp, method, path and raw body using your API secret. The timestamp must be within 300 seconds of server time.
message = timestamp + "." + METHOD + "." + path + "." + body signature = HEX( HMAC_SHA256(secret, message) )
// PHP example
$timestamp = time();
$body = json_encode($payload);
$message = $timestamp.".".strtoupper($method).".".$path.".".$body;
$signature = hash_hmac('sha256', $message, $apiSecret);
Currencies
Returns the assets enabled for your account together with limits and effective commission rates.
{
"data": [
{
"code": "USDT_TRC20",
"name": "Tether USD (TRC20)",
"network": "TRON",
"decimals": 6,
"deposits_enabled": true,
"withdrawals_enabled": true,
"limits": { "min_deposit": "1.00000000", "min_withdrawal": "10.00000000" }
}
]
}
Deposits
{
"asset": "USDT_TRC20",
"amount": "100.00",
"external_id": "order-1024",
"description": "Wallet top-up",
"callback_url": "https://yoursite.com/webhooks/tridipay",
"metadata": { "user_id": 42 }
}
Response:
{
"data": {
"id": "9f3c...uuid",
"reference": "DEP-XXXX",
"status": "pending",
"asset": "USDT_TRC20",
"amount_requested": "100.00000000",
"payment_address": "TXY...abc",
"checkout_url": "https://tridipay.com/checkout/9f3c...uuid",
"qr_code": "data:image/png;base64,...",
"expires_at": "2026-01-01T12:00:00+00:00"
}
}
Withdrawals
{
"asset": "USDT_TRC20",
"amount": "50.00",
"to_address": "TReceiverAddress...",
"external_id": "payout-77"
}
The commission and the payout amount are deducted from your balance immediately. The payout is broadcast from the platform signing wallet.
Balance
Transactions
Webhooks
We POST a JSON payload to your webhook URL for every relevant event. Verify the signature before trusting the payload.
// Verify webhook signature (PHP)
$header = $request->header('X-TridiPay-Signature');
parse_str(str_replace(',', '&', $header), $parts); // t=...,v1=...
$expected = 't='.$parts['t'].',v1='.hash_hmac('sha256', $parts['t'].'.'.$request->getContent(), $webhookSecret);
$valid = hash_equals($expected, $header);
Errors
{
"error": { "code": "insufficient_balance", "message": "Insufficient available balance." }
}
| invalid_api_key | The API key is missing or invalid. |
| invalid_signature | The signature does not match. |
| signature_expired | The request timestamp is too old. |
| insufficient_scope | The key lacks the required scope. |
| ip_not_allowed | The request IP is not whitelisted. |
| tenant_inactive | The merchant account is suspended. |
| unsupported_asset | Unknown or disabled asset. |
| below_minimum | Amount below the configured minimum. |
| invalid_address | Invalid destination address. |
| insufficient_balance | Not enough available balance. |
| not_found | Resource not found. |