ZyloPaydocs

Changelog

Every change to the ZyloPay public API, newest first.

Changes to the public API, newest first. Breaking changes ship only in a new dated version; see Versioning.

2026-09-28: API v1

The first public version of the ZyloPay API.

  • API version 2026-09-28 (the only dated version).
  • Resources: payment intents (create, retrieve, list, cancel), payments (retrieve, list), refunds (create, retrieve, list), terminals (retrieve, list), balance, events (30 days), webhook endpoints and deliveries.
  • API keys: zp_test_… (testnet sandbox) and zp_live_… (mainnet), scopes, IP allowlist, expiry, rotation with overlap, audit log.
  • Webhooks: 16 event types, signed with ZyloPay-Signature (HMAC-SHA256), retried for 3 days, automatic disabling of failing endpoints, secret rotation with dual signatures, test events and resends.
  • Conventions: Idempotency-Key (required for payment intents and refunds, 48-hour replay), cursor pagination, one error format with stable codes, Request-Id, RateLimit-* headers.

Known limitations

  • The ZyloPay POS app picks up API-created payment intents from the release that adds intent pickup, which is rolling out. Terminal-started payments are fully visible through the API and webhooks.
  • Withdrawals and payouts are not in the API. Use the dashboard.
  • Publishable keys (zp_…_pk_…) have no access yet.
  • @zylopay/node is pre-release.

On this page