PAYOUP

API Terms of Service

Comprehensive terms for developers integrating with the Payoup platform API.

Last updated: September 2026

1. Overview

Welcome to the Payoup API (Application Programming Interface). These API Terms of Service ("API Terms") govern your access to and use of Payoup's API services, developer tools, and related documentation (collectively, the "API Services"). By using the API Services, you agree to be bound by these API Terms and the Payoup Terms of Service.

Important: These API Terms are supplemental to the Payoup Terms of Service. In case of conflict, these API Terms shall govern your use of the API Services.

2. API Access and Registration

To access the Payoup API, you must:

  • Have an active Payoup account in good standing
  • Complete the required verification and compliance checks
  • Register for API access through your developer dashboard
  • Accept these API Terms and any applicable additional terms
  • Obtain and securely manage API credentials (API keys, tokens)

API Keys: You will receive unique API credentials that must be kept confidential and used only by your authorized applications.

3. API Endpoints and Features

The Payoup API provides the following core functionalities:

Method Endpoint Description
POST /v1/payment-links Create payment link
POST /v1/webhook/register Webhook registration
GET /v1/transaction/{id} Transaction lookup
POST /v1/transfer/initiate Initiate transfer
GET /v1/balance Balance inquiry

4. Rate Limits and Usage Quotas

API usage is subject to rate limits based on your subscription plan:

  • Starter Plan: 1,000 requests per hour
  • Professional Plan: 5,000 requests per hour
  • Scale Plan: 20,000 requests per hour
  • Enterprise Plan: Custom limits tailored to your needs

5. Authentication and Security

All API requests must be authenticated using one of the following methods:

  • API Key Authentication: Include your API key in the Authorization header
  • OAuth 2.0: Use access tokens for user-specific operations
  • Webhook Signatures: Verify webhook requests using HMAC signatures

5.1 Security Requirements

  • Use HTTPS for all API communications
  • Never expose API keys in client-side code
  • Implement proper error handling and logging
  • Validate all input data and API responses
  • Use secure storage for API credentials
  • Implement rate limiting on your end

Authorization: Bearer pk_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Content-Type: application/json X-Payoup-Version: 2024-02-23

6. Data and Privacy

Your use of the API Services is subject to Payoup's privacy practices:

  • Data Processing: API requests and responses may be logged for security and monitoring purposes
  • Data Retention: API logs are retained for up to 90 days for security analysis
  • Data Sharing: API data is not shared with third parties except as required by law
  • Data Security: All API communications are encrypted using TLS 1.2 or higher
  • User Consent: Ensure you have proper consent before processing user data via API

7. Webhooks

Payoup provides webhook notifications for real-time event updates:

  • Payment Events: payment.created, payment.completed, payment.failed
  • Account Events: account.verified, account.suspended
  • Payout Events: payout.initiated, payout.completed, payout.failed
  • Dispute Events: dispute.created, dispute.resolved

7.1 Webhook Requirements

  • Webhook endpoints must respond with HTTP 200 status within 10 seconds
  • Implement retry logic for failed webhook deliveries
  • Verify webhook signatures using your webhook secret
  • Handle duplicate webhook events gracefully
  • Use HTTPS for all webhook endpoints

8. Prohibited API Uses

The following uses of the Payoup API are strictly prohibited:

  • Reverse Engineering: Attempting to reverse engineer or decompile the API
  • Excessive Usage: Exceeding rate limits or implementing abusive retry patterns
  • Data Mining: Using the API to collect user data without consent
  • Competitive Services: Creating competing technology or payment infrastructure services that replicate Payoup's core platform
  • Security Exploitation: Attempting to find or exploit security vulnerabilities
  • Spam and Abuse: Using the API for spam, fraud, or malicious activities
  • Resale: Reselling API access or creating API proxy services

9. API Availability and SLA

Payoup strives to maintain high API availability:

  • Uptime Target: 99.9% monthly uptime for API services
  • Response Time: Average response time under 200ms
  • Maintenance Windows: Scheduled maintenance announced 24 hours in advance
  • Status Page: Real-time API status available at status.payoup.com
  • Incident Response: Critical incidents addressed within 1 hour

Note: Service Level Agreement (SLA) credits may be available for Enterprise customers in case of prolonged outages.

10. API Versioning and Deprecation

Payoup follows semantic versioning for API releases:

  • Version Format: API versions are identified by date (e.g., 2024-02-23)
  • Backward Compatibility: Breaking changes require new version releases
  • Deprecation Notice: 6 months notice before version deprecation
  • Migration Support: Documentation and support provided for version upgrades
  • Concurrent Versions: Multiple API versions supported simultaneously

11. Testing and Sandbox

Payoup provides a sandbox environment for testing:

  • Sandbox API: Separate sandbox endpoint (api-sandbox.payoup.com)
  • Test Data: Use test payment methods and dummy data
  • No Real Transactions: Sandbox operations do not process real payments
  • Full Feature Access: All API features available in sandbox
  • Isolated Environment: Sandbox data is separate from production

12. Support and Documentation

Payoup provides comprehensive API support:

  • API Documentation: Complete documentation at docs.payoup.com
  • Code Examples: SDKs and examples for popular programming languages
  • Developer Support: Email support at support@payoup.com
  • Community Forum: Developer community for questions and discussions
  • Status Monitoring: Real-time API status and incident updates

13. Compliance and Legal

API usage must comply with all applicable laws and regulations:

  • Financial Regulations: Comply with AML, KYC, and financial regulations
  • Data Protection: Follow GDPR, CCPA, and privacy laws
  • Export Controls: Comply with export control and sanctions regulations
  • Industry Standards: Follow PCI DSS and security standards
  • Local Laws: Comply with laws in all jurisdictions where you operate

14. Termination and Suspension

Payoup may suspend or terminate API access for:

  • Violation of these API Terms or Payoup Terms of Service
  • Suspicious or fraudulent API usage patterns
  • Security breaches or compromised API credentials
  • Excessive rate limit violations or abuse
  • Non-payment of applicable fees
  • Regulatory or legal compliance issues

Notice: We will provide reasonable notice before termination, except in cases of immediate security threats or legal violations.

15. Contact and Support

For API-related questions and support:

15. Contact and Support

support@payoup.com
Enexfi LTD, 128 City Road, London, EC1V 2NX, UNITED KINGDOM