payment:write: create or cancel Payments and disable Checkout access.payment:read: query payment status and verify pricing configuration.webhook:bootstrap: configure a Webhook endpoint and verify its signing Secret.Authorization: Bearer <API_KEY>; never put an API Key in browser code, a URL, screenshots or logs. To replace a Key, issue a new one, deploy and verify it, and revoke the old one in your TLY Pay dashboard.TLY_API_ORIGIN and TLY_API_KEY configuration. Set HOSTED_CHECKOUT_ORIGIN to the supplied Checkout origin.https://api.tlypay.com. Keep your API Key in server-side configuration.GET /v1/store with your API Key to verify the configured pricing source and website domain before building the request. Use the returned primary_source kind, ref and decimals to construct source_amount. Do not infer Payment pricing from Display currency or from the asset your customer will pay with.curl --request POST "${TLY_API_ORIGIN}/v1/payments" \
--header "Authorization: Bearer ${TLY_API_KEY}" \
--header "Content-Type: application/json" \
--header "Idempotency-Key: order-example-1048" \
--data '{"order_ref":"ORDER-EXAMPLE-1048","source_amount":{"kind":"fiat","currency":"USD","amount_raw":"12800"}}'source_amount must match your configured primary pricing source. USD 12800 means USD 128.00. Use positive integer strings without leading zeros, not floating-point numbers. The service determines decimals. For crypto pricing, provide kind: "crypto", your configured pricing_ref, and amount_raw; do not substitute a token contract address or a network ID for a pricing ref.order_ref is optional and is not a unique key. Keep one Idempotency-Key for each creation intent and reuse both that Key and the same request body after a timeout. A successful create or identical replay returns HTTP 200, not 201. Creating a Payment does not mark the order paid.payment_id with your order. Use it to open Checkout, query payment status and identify the Payment when contacting support. You and your customers use the same ID, which can be displayed and copied. Checkout remains subject to website authorization, risk checks, expiry and access restrictions. Queries and changes from your server require your API Key.HOSTED_CHECKOUT_ORIGIN with /#payment_id=<payment_id>. For Embedded Checkout, load the supplied Embedded Checkout script at /widget/crypto-pay.js once on your website and call window.CryptoPay.open({ paymentId }) with the returned Payment ID. The Hosted Checkout URL carries the same ID in its fragment. Your customer opens Checkout to start paying; creating a link alone does not prove payment./v1/* at TLY_API_ORIGIN; never expose your API Key to browser code.checkout_origin in the create request with the HTTPS origin permitted by Website (optional). Omitting it uses the configured Hosted Checkout origin. Saving a website in your TLY Pay dashboard alone does not change the origin of an API-created Payment.payment.updated Webhook, or query GET /v1/payments/{payment_id} from your server with payment:read. Query responses describe authoritative payment facts. A browser redirect or Webhook delivery result is not a payment receipt.status_version as described in the Webhook guide.POST /v1/payments/{payment_id}/cancel. Repeating a successful cancellation reads the current state.DELETE /v1/payments/{payment_id}/consumer-access. Customers will no longer be able to access this Payment through Checkout. Its payment status is unchanged; you can still query the Payment from your server.GET /v1/store to verify the API Key's configured pricing source and website domain.