Introduction
Every endpoint of the ZyloPay API v1, generated from the OpenAPI 3.1 specification.
The ZyloPay API is organised around REST. It accepts JSON bodies, returns JSON, uses standard HTTP status codes and authenticates with a secret API key sent as a bearer token. The key chooses the mode: zp_test_sk_… works on the Monad testnet sandbox, zp_live_sk_… on mainnet. Nothing else changes between modes.
Base URL
https://zylopay-api.fly.dev/api/v1Current API version: 2026-09-28 (see versioning). The OpenAPI 3.1 document behind this reference is at /openapi/v1.json: use it to generate clients or import the API into a tool.
Authentication
curl https://zylopay-api.fly.dev/api/v1/balance \
-H "Authorization: Bearer $ZYLOPAY_SECRET_KEY"Read Authentication for scopes, rotation and the IP allowlist.
Every endpoint has a curl example and a Node example with @zylopay/node. The Node SDK is pre-release: it is not on npm yet.
Endpoints
Payment intents
| Endpoint | Description |
|---|---|
| The payment intent object | PaymentIntent attributes and an example |
GET /v1/payment_intents | List payment intents |
POST /v1/payment_intents | Create a payment intent |
GET /v1/payment_intents/{id} | Retrieve a payment intent |
POST /v1/payment_intents/{id}/cancel | Cancel a payment intent |
Payments
| Endpoint | Description |
|---|---|
| The payment object | Payment attributes and an example |
GET /v1/payments | List payments |
GET /v1/payments/{id} | Retrieve a payment |
Refunds
| Endpoint | Description |
|---|---|
| The refund object | Refund attributes and an example |
GET /v1/refunds | List refunds |
POST /v1/refunds | Create a refund |
GET /v1/refunds/{id} | Retrieve a refund |
Terminals
| Endpoint | Description |
|---|---|
| The terminal object | Terminal attributes and an example |
GET /v1/terminals | List terminals |
GET /v1/terminals/{id} | Retrieve a terminal |
Balance
| Endpoint | Description |
|---|---|
| The balance object | Balance attributes and an example |
GET /v1/balance | Retrieve the balance |
Events
| Endpoint | Description |
|---|---|
| The event object | Event attributes and an example |
GET /v1/events | List events |
GET /v1/events/{id} | Retrieve an event |
Webhook endpoints
| Endpoint | Description |
|---|---|
| The webhook endpoint object | WebhookEndpoint attributes and an example |
| The webhook delivery object | WebhookDelivery attributes and an example |
GET /v1/webhook_deliveries/{id} | Retrieve a delivery |
POST /v1/webhook_deliveries/{id}/retry | Resend a delivery |
GET /v1/webhook_endpoints | List webhook endpoints |
POST /v1/webhook_endpoints | Create a webhook endpoint |
GET /v1/webhook_endpoints/{id} | Retrieve a webhook endpoint |
PATCH /v1/webhook_endpoints/{id} | Update a webhook endpoint |
DELETE /v1/webhook_endpoints/{id} | Delete a webhook endpoint |
GET /v1/webhook_endpoints/{id}/deliveries | List deliveries of an endpoint |
POST /v1/webhook_endpoints/{id}/rotate_secret | Rotate the signing secret |
POST /v1/webhook_endpoints/{id}/test | Send a test event |
Webhooks
- Event types: every event and its payload.
- Error codes: every error and decline code.