easyway
Create account

Security

What happens to the money your customers send, who can move it, and how your integration can check that every message really comes from us. This page describes what exists today, nothing more.

How your balance is held

easyway is a custodial gateway. Payments arrive on addresses controlled by easyway; once confirmed, the amount (minus the fee) is credited to your balance in our ledger, and it stays with us until you withdraw it to a wallet of your own. If you prefer not to hold a balance with us, withdraw regularly, by hand or through the API.

Funds are split between a hot wallet, which pays out day-to-day withdrawals, and a cold wallet on a hardware device that never touches a server. Everything above what the hot wallet needs is moved to cold storage.

Keys stay off the API server

The server that answers the API and the dashboard holds only watch-only public keys: it can derive a fresh deposit address for every invoice, but it cannot spend from any of them. Transactions are signed by a separate signer process on its own machine, which accepts no inbound network connections and only picks up withdrawal jobs that the API has already checked.

When a payment counts as paid

A payment is credited only after enough blocks have been built on top of it for the network to consider it final. For TON, the Bitcoin family, the XRP Ledger and Solana, a payment is additionally confirmed against a second, independent data source before it is credited.

NetworkConfirmationsHow payments are matched
TRON19A new address for every invoice
BNB Smart Chain15A new address for every invoice
TON1One address, comment per invoice
Ethereum12A new address for every invoice
Bitcoin2A new address for every invoice
Litecoin4A new address for every invoice
Dogecoin6A new address for every invoice
XRP Ledger1One account, destination tag per invoice
Solana1A new address for every invoice
Polygon64A new address for every invoice
Avalanche10A new address for every invoice
Dash4A new address for every invoice

Who can withdraw

Two-factor authentication

Accounts support time-based one-time codes (TOTP, RFC 6238), which work with Google Authenticator, Authy, 1Password and similar apps. In live mode, a withdrawal, adding a withdrawal address, and creating an API key that can send payouts all require 2FA to be switched on and a fresh code.

Address whitelist

Live withdrawals can only go to addresses you have added to your whitelist in the dashboard, and each new address triggers an email notice to the account owner. A withdrawal requested through the API is held to the same list, so a leaked API key cannot send your balance to anyone else's wallet.

Activity log

Sensitive actions (API keys created or revoked, whitelist changes, 2FA changes, withdrawals requested) are recorded with the time and IP address, and you can review them in the dashboard.

API keys

Secret keys are shown once, when you create them, and stored only as a keyed hash. Each key carries scopes (for example invoices:write without payouts:write) and an optional IP allowlist. Test and live keys are separate, and test keys never touch a blockchain.

Signed webhooks

Every webhook carries an X-Webhook-Signature: t=…,v1=… header: an HMAC-SHA256 of the timestamp and the raw body, made with your endpoint's secret. Checking it (and rejecting old timestamps) proves the event came from easyway and was not replayed. Failed deliveries are retried 8 times with growing delays over about 45 hours. Verification code for Node.js, PHP and Python is in the webhooks documentation.

Reporting a vulnerability

If you find a security problem, email support@easyway.cash with the details and how to reproduce it. Please give us a chance to fix it before telling anyone else.

Create a merchant accountRead the API docs
Security: how we hold and protect your funds | easyway