Secure global payments without adding custody risk.
Launch with clear security boundaries: payer authorization in wallet flow, merchant-direct settlement, and signed backend events your team can verify.
Security control console
Current controls only
Custody
Private keys remain with merchant wallets
Webhook
HMAC signature validation supported
API key
Regeneration available in dashboard
Orders
Duplicate order IDs rejected per merchant
Payer wallet
Authorizes payment
Trezalink
Creates session and signs events
Merchant wallet
Receives settlement
Protection you can scan in five seconds.
These are active platform controls available in current product flows.
Custody model
Wallet-direct settlement
Merchant funds are not held by Trezalink.
Webhook integrity
HMAC signature support
Verify event origin with webhook secrets.
Credential hygiene
API key rotation
Regenerate merchant API keys from dashboard.
Order safety
Duplicate order protection
Reused order IDs are rejected per merchant.
Merchant control stays explicit at every sensitive edge.
Trezalink coordinates checkout sessions, settlement records, and signed events while merchant teams keep ownership of wallet custody and backend secret handling.
Payer authorization happens in wallet flow, not through shared platform custody.
Settlement goes directly to merchant wallet after payment confirmation.
Operational events can be validated via webhook signatures and logs.
Security boundaries are explicit between platform controls and merchant secrets.
Clear ownership for each secret.
API key
Merchant: Store securely and rotate on schedule.
Trezalink: Provide key regeneration in the dashboard.
Webhook secret
Merchant: Validate incoming signatures in backend handlers.
Trezalink: Sign payloads and expose delivery/webhook logs.
Wallet key
Merchant: Maintain wallet custody and signing control.
Trezalink: Never request or store private keys.
Security controls your ops and dev teams can reason about.
Keep the checkout surface simple while preserving verification, credential hygiene, status context, and reconciliation details around every payment flow.
Read security docsPrivate-key boundary
Merchant wallet keys stay outside Trezalink systems and remain under merchant wallet control.
Webhook verification
Backend events can be validated with HMAC signatures before fulfillment logic runs.
Credential rotation
Merchant API credentials can be regenerated from the dashboard when teams rotate secrets.
Duplicate order protection
Reused order IDs are blocked per merchant to reduce accidental duplicate checkout state.
Status visibility
Public status and product reporting surfaces help teams separate incidents from integration issues.
Finance-ready logs
Payment records, webhook logs, and fee details support reconciliation after settlement.
Answers before go-live.
Does Trezalink ever access merchant private keys?
No. Merchant private keys remain with the wallet provider and are never handled by Trezalink.
How do we verify webhook authenticity?
Use your webhook secret to validate the X-Trezalink-Signature HMAC value on every incoming event.
How is settlement finalized?
Payments settle after on-chain confirmation and are recorded with fee and net details for reconciliation.
Where can teams monitor reliability?
Status and operational transparency are available through the public status and product reporting surfaces.
Launch Solana payments with boundaries your team can explain.
Start accepting global payments with non-custodial settlement, signed events, and clear ownership for merchant secrets.