[{"data":1,"prerenderedAt":874},["ShallowReactive",2],{"navigation-en":3,"en:\u002Fterms\u002Fsettlement-and-terms":208,"en:\u002Fterms\u002Fsettlement-and-terms:surround":869},[4,20,30,61,92,110,125,148,173,187],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":6},"Getting Started",false,"\u002Fgetting-started","1.getting-started",[10,15],{"title":11,"path":12,"stem":13,"icon":14},"Portal Preparation","\u002Fgetting-started\u002Fportal-setup","1.getting-started\u002F1.portal-setup","i-lucide-rocket",{"title":16,"path":17,"stem":18,"icon":19},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-zap",{"title":21,"icon":22,"path":23,"stem":24,"children":25,"page":6},"Service & Terms","i-lucide-scale","\u002Fterms","10.terms",[26],{"title":27,"path":28,"stem":29,"icon":22},"Settlement & Service Terms","\u002Fterms\u002Fsettlement-and-terms","10.terms\u002F1.settlement-and-terms",{"title":31,"icon":32,"path":33,"stem":34,"children":35,"page":6},"Core Concepts","i-lucide-key-round","\u002Fconcepts","2.concepts",[36,41,46,51,56],{"title":37,"path":38,"stem":39,"icon":40},"Authentication","\u002Fconcepts\u002Fauthentication","2.concepts\u002F1.authentication","i-lucide-fingerprint",{"title":42,"path":43,"stem":44,"icon":45},"IP Allowlist","\u002Fconcepts\u002Fip-allowlist","2.concepts\u002F2.ip-allowlist","i-lucide-shield-check",{"title":47,"path":48,"stem":49,"icon":50},"Money Format","\u002Fconcepts\u002Fmoney","2.concepts\u002F3.money","i-lucide-banknote",{"title":52,"path":53,"stem":54,"icon":55},"Idempotency","\u002Fconcepts\u002Fidempotency","2.concepts\u002F4.idempotency","i-lucide-repeat",{"title":57,"path":58,"stem":59,"icon":60},"Error envelope & codes","\u002Fconcepts\u002Ferrors","2.concepts\u002F5.errors","i-lucide-octagon-alert",{"title":62,"icon":63,"path":64,"stem":65,"children":66,"page":6},"Deposits","i-lucide-arrow-down-to-line","\u002Fdeposits","3.deposits",[67,72,77,82,87],{"title":68,"path":69,"stem":70,"icon":71},"Deposit Overview & State Machine","\u002Fdeposits\u002Foverview","3.deposits\u002F1.overview","i-lucide-info",{"title":73,"path":74,"stem":75,"icon":76},"Create a Deposit","\u002Fdeposits\u002Fcreate","3.deposits\u002F2.create","i-lucide-plus",{"title":78,"path":79,"stem":80,"icon":81},"Get a Deposit","\u002Fdeposits\u002Fretrieve","3.deposits\u002F3.retrieve","i-lucide-search",{"title":83,"path":84,"stem":85,"icon":86},"Cancel a Deposit","\u002Fdeposits\u002Fcancel","3.deposits\u002F4.cancel","i-lucide-x",{"title":88,"path":89,"stem":90,"icon":91},"Hosted Cashier Page","\u002Fdeposits\u002Fcashier","3.deposits\u002F5.cashier","i-lucide-external-link",{"title":93,"icon":94,"path":95,"stem":96,"children":97,"page":6},"Withdrawals","i-lucide-arrow-up-from-line","\u002Fwithdrawals","4.withdrawals",[98,102,106],{"title":99,"path":100,"stem":101,"icon":71},"Withdrawal Overview","\u002Fwithdrawals\u002Foverview","4.withdrawals\u002F1.overview",{"title":103,"path":104,"stem":105,"icon":76},"Create a Withdrawal","\u002Fwithdrawals\u002Fcreate","4.withdrawals\u002F2.create",{"title":107,"path":108,"stem":109,"icon":81},"Get & List Withdrawals","\u002Fwithdrawals\u002Fretrieve","4.withdrawals\u002F3.retrieve",{"title":111,"icon":112,"path":113,"stem":114,"children":115,"page":6},"Balance & Banks","i-lucide-wallet","\u002Fbalance","5.balance",[116,120],{"title":117,"path":118,"stem":119,"icon":112},"Get Balance","\u002Fbalance\u002Fget-balance","5.balance\u002F1.get-balance",{"title":121,"path":122,"stem":123,"icon":124},"Bank List","\u002Fbalance\u002Fbanks","5.balance\u002F2.banks","i-lucide-landmark",{"title":126,"icon":127,"path":128,"stem":129,"children":130,"page":6},"Webhooks","i-lucide-webhook","\u002Fwebhooks","6.webhooks",[131,135,140,144],{"title":132,"path":133,"stem":134,"icon":71},"Webhook Overview","\u002Fwebhooks\u002Foverview","6.webhooks\u002F1.overview",{"title":136,"path":137,"stem":138,"icon":139},"Event Catalog & Payloads","\u002Fwebhooks\u002Fevents","6.webhooks\u002F2.events","i-lucide-list",{"title":141,"path":142,"stem":143,"icon":45},"Signature Verification","\u002Fwebhooks\u002Fsignature-verification","6.webhooks\u002F3.signature-verification",{"title":145,"path":146,"stem":147,"icon":55},"Endpoint Requirements, Retries & SSRF","\u002Fwebhooks\u002Fdelivery-and-retries","6.webhooks\u002F4.delivery-and-retries",{"title":149,"icon":150,"path":151,"stem":152,"children":153,"page":6},"Sandbox","i-lucide-flask-conical","\u002Fsandbox","7.sandbox",[154,158,163,168],{"title":155,"path":156,"stem":157,"icon":71},"Test Mode Overview","\u002Fsandbox\u002Foverview","7.sandbox\u002F1.overview",{"title":159,"path":160,"stem":161,"icon":162},"Simulate Transfer","\u002Fsandbox\u002Fsimulate-transfer","7.sandbox\u002F2.simulate-transfer","i-lucide-banknote-arrow-down",{"title":164,"path":165,"stem":166,"icon":167},"Top-up & Reset","\u002Fsandbox\u002Ftop-up-and-reset","7.sandbox\u002F3.top-up-and-reset","i-lucide-rotate-ccw",{"title":169,"path":170,"stem":171,"icon":172},"End-to-End Test Flow","\u002Fsandbox\u002Fe2e-test-flow","7.sandbox\u002F4.e2e-test-flow","i-lucide-list-checks",{"title":174,"icon":14,"path":175,"stem":176,"children":177,"page":6},"Go-live","\u002Fgo-live","8.go-live",[178,182],{"title":179,"path":180,"stem":181,"icon":172},"Go-live Checklist","\u002Fgo-live\u002Fchecklist","8.go-live\u002F1.checklist",{"title":183,"path":184,"stem":185,"icon":186},"Contact & Support","\u002Fgo-live\u002Fsupport","8.go-live\u002F2.support","i-lucide-life-buoy",{"title":188,"icon":189,"path":190,"stem":191,"children":192,"page":6},"Reference","i-lucide-book-marked","\u002Freference","9.reference",[193,198,203],{"title":194,"path":195,"stem":196,"icon":197},"Endpoint Catalog","\u002Freference\u002Fendpoints","9.reference\u002F1.endpoints","i-lucide-table",{"title":199,"path":200,"stem":201,"icon":202},"Code Samples (Node.js & PHP)","\u002Freference\u002Fcode-samples","9.reference\u002F2.code-samples","i-lucide-code",{"title":204,"path":205,"stem":206,"icon":207},"Status Values & Glossary","\u002Freference\u002Fglossary-states","9.reference\u002F3.glossary-states","i-lucide-book-a",{"id":209,"title":27,"badge":210,"body":211,"description":863,"extension":864,"links":210,"meta":865,"method":210,"navigation":866,"path":28,"seo":867,"stem":29,"__hash__":868},"docs_en\u002F10.terms\u002F1.settlement-and-terms.md",null,{"type":212,"value":213,"toc":849},"minimark",[214,223,250,255,258,289,295,299,342,357,362,366,384,387,416,426,430,437,445,449,458,469,473,496,519,525,564,571,579,640,679,692,733,750,779,800,803,810,814,821,825],[215,216,217,218,222],"p",{},"This page summarises the commercial and operational terms of the UnknownPay service: how your balance is ",[219,220,221],"strong",{},"settled"," back to you, the transaction limits, service hours, and the acceptable-use rules your account must follow.",[224,225,226],"note",{},[215,227,228,229,232,233,237,238,241,242,245,246,249],{},"These are service \u002F commercial terms, not an S2S API surface. ",[219,230,231],{},"Settlement runs from UnknownPay to you"," — it is not an endpoint your server calls. (Sending ",[234,235,236],"code",{},"kind=settlement"," to ",[234,239,240],{},"POST \u002Fv1\u002Fwithdrawals"," is rejected with ",[234,243,244],{},"422 INVALID_KIND"," — see ",[247,248,103],"a",{"href":104},".)",[251,252,254],"h2",{"id":253},"payment-methods","Payment methods",[215,256,257],{},"Deposits can be collected over two channels:",[259,260,261,276],"ul",{},[262,263,264,267,268,271,272,275],"li",{},[219,265,266],{},"PromptPay QR"," (",[234,269,270],{},"PROMPTPAY_QR",") — the default; render ",[234,273,274],{},"qr_payload"," for the customer to scan.",[262,277,278,267,281,284,285,288],{},[219,279,280],{},"Bank transfer",[234,282,283],{},"BANK_TRANSFER",") — show ",[234,286,287],{},"pay_to"," for a manual transfer.",[215,290,291,292,294],{},"See ",[247,293,62],{"href":69}," for the full flow.",[251,296,298],{"id":297},"transaction-limits","Transaction limits",[300,301,302,318],"table",{},[303,304,305],"thead",{},[306,307,308,312,315],"tr",{},[309,310,311],"th",{},"Operation",[309,313,314],{},"Minimum",[309,316,317],{},"Maximum",[319,320,321,333],"tbody",{},[306,322,323,327,330],{},[324,325,326],"td",{},"Deposit (pay-in)",[324,328,329],{},"100 THB",[324,331,332],{},"1,000,000 THB",[306,334,335,338,340],{},[324,336,337],{},"Withdrawal (pay-out)",[324,339,329],{},[324,341,332],{},[215,343,344,345,348,349,352,353,356],{},"Amounts are sent as ",[219,346,347],{},"baht strings"," (e.g. ",[234,350,351],{},"\"100.00\"","). A value outside this range is rejected with ",[234,354,355],{},"422 INVALID_AMOUNT",".",[224,358,359],{},[215,360,361],{},"Limits may be tailored to your account under your agreement — the values above are the standard service limits.",[251,363,365],{"id":364},"settlement","Settlement",[215,367,368,370,371,374,375,378,379,383],{},[219,369,365],{}," is how UnknownPay pays your ",[219,372,373],{},"available balance"," back to you. It is separate from a ",[247,376,377],{"href":100},"withdrawal",", which is a payout ",[380,381,382],"em",{},"you"," send to a customer \u002F destination account.",[215,385,386],{},"You can be settled in either currency:",[259,388,389,395],{},[262,390,391,394],{},[219,392,393],{},"THB — 0% spread."," Settled at face value, with no conversion spread.",[262,396,397,400,401,404,405,408,409,412,413,356],{},[219,398,399],{},"USDT — up to ±5% spread."," The conversion rate is derived from ",[219,402,403],{},"CoinGecko"," and ",[219,406,407],{},"Coinbase"," reference rates, and the rate applied may differ from the market mid-rate by up to ±5% (the spread). Minimum ",[219,410,411],{},"1,000 USDT"," per USDT settlement, processed ",[219,414,415],{},"within 24 hours",[215,417,418,421,422,425],{},[219,419,420],{},"Daily force settlement."," UnknownPay may automatically settle your balance once per day. The trigger threshold and the amount to settle are ",[219,423,424],{},"configured per account"," — when your settle-able balance rises above the configured threshold, the system settles out the configured amount.",[251,427,429],{"id":428},"service-hours-maintenance","Service hours & maintenance",[215,431,432,433,436],{},"The service is ",[219,434,435],{},"unavailable between 23:00 and 02:00 (UTC+7)"," for routine maintenance, and may also be unavailable outside these hours when announced by the partner bank.",[259,438,439,442],{},[262,440,441],{},"During a window, transactional calls may be rejected or delayed — retry after the window closes.",[262,443,444],{},"Bank-driven maintenance is announced ahead of time where possible; the 23:00–02:00 (UTC+7) window is the usual default.",[251,446,448],{"id":447},"supported-merchants-acceptable-use","Supported merchants & acceptable use",[450,451,452],"warning",{},[215,453,454,455],{},"This service ",[219,456,457],{},"exclusively supports Gambling and Forex merchants.",[259,459,460],{},[262,461,462,465,466],{},[219,463,464],{},"Prohibited funds."," Funds originating from scams, fraud, or call-center scams are ",[219,467,468],{},"strictly prohibited.",[251,470,472],{"id":471},"merchant-responsibility-liability","Merchant responsibility & liability",[450,474,475],{},[215,476,477,480,481,484,485,488,489,492,493,356],{},[219,478,479],{},"You are solely responsible for validating your own end customers and for every action taken with your credentials."," An approved — or even ",[234,482,483],{},"SUCCESS"," — payout is ",[219,486,487],{},"not"," UnknownPay's confirmation that the underlying end-customer transaction was legitimate; it confirms one thing only: your ",[234,490,491],{},"pool"," held sufficient funds at that moment. To the extent permitted by applicable law, losses arising from your own negligence, a weak or misconfigured integration, a compromise of your systems or credentials, or fraud originating on your side are ",[219,494,495],{},"your responsibility, not UnknownPay's",[215,497,498,499,504,505,508,509,511,512,514,515,518],{},"UnknownPay operates at the ",[219,500,501,502],{},"merchant ",[234,503,491],{}," level. We can see and control the balance of ",[380,506,507],{},"your"," ",[234,510,491],{}," — your UnknownPay wallet, exposed via ",[247,513,117],{"href":118}," — but we have ",[219,516,517],{},"no visibility into the ledger inside your platform",": the per-player \u002F per-user balances and entitlements of your own end customers. That ledger lives entirely on your side, and only you can read it.",[215,520,521,522,524],{},"Because of this boundary, when you submit a ",[247,523,377],{"href":100},":",[259,526,527,540,546],{},[262,528,529,530,536,537,539],{},"UnknownPay validates the request ",[219,531,532,533,535],{},"against your ",[234,534,491],{}," balance only",". If the ",[234,538,491],{}," is funded, the payout can be approved and dispatched.",[262,541,542,543,545],{},"That check is ",[219,544,487],{}," a verification that the end customer requesting the money actually held a real, withdrawable balance on your site. UnknownPay is structurally unable to perform that check — only your system can.",[262,547,548,549,552,553,556,557,559,560,563],{},"You are therefore ",[219,550,551],{},"solely responsible"," for validating each end customer's entitlement and balance ",[219,554,555],{},"before"," you call ",[234,558,240],{},", and for ",[219,561,562],{},"all"," activity performed with your credentials.",[215,565,566,567,570],{},"A correctly signed request from an allowed IP ",[219,568,569],{},"is"," your request, and you are bound by it. UnknownPay cannot distinguish a genuine request from one made with leaked, shared, stolen, or misused credentials — whether they are used by you, your staff, your agents, or any third party who obtains them.",[215,572,573,576,577,524],{},[219,574,575],{},"Securing your side is your obligation."," Treat your credentials as the keys to your ",[234,578,491],{},[259,580,581,601,621,630],{},[262,582,583,586,587,590,591,594,595,598,599,356],{},[219,584,585],{},"Protect your show-once secrets."," Your API key ",[234,588,589],{},"secret"," (used to HMAC-sign every request) and your ",[234,592,593],{},"webhook"," signing secret are each shown ",[219,596,597],{},"only once",", at rotate time, and are never recoverable afterwards. Store them in a secrets manager — never in source control, client-side code, or logs — and rotate immediately if one is exposed. See ",[247,600,37],{"href":38},[262,602,603,606,607,610,611,613,614,616,617,620],{},[219,604,605],{},"Sign and verify everything."," Every S2S request must carry a valid ",[234,608,609],{},"X-Api-Key"," and a matching HMAC signature, and every inbound webhook must be verified on its raw bytes ",[219,612,555],{}," you act on it, so a forged event can never drive your business logic. See ",[247,615,141],{"href":142},". Never treat the synchronous ",[234,618,619],{},"PENDING"," response as final.",[262,622,623,626,627,629],{},[219,624,625],{},"Lock down the network."," Maintain the S2S source IPs you call from so the ",[247,628,42],{"href":43}," admits only your own servers.",[262,631,632,635,636,639],{},[219,633,634],{},"Prevent replay and duplication."," Send a unique ",[234,637,638],{},"Idempotency-Key"," per payout so a retried or replayed request cannot pay out twice.",[641,642,643],"caution",{},[215,644,645,651,652,654,655,658,659,662,663,665,666,669,670,672,673,675,676,678],{},[219,646,647,648,650],{},"Why this matters — ",[234,649,491],{}," drain."," Your ",[234,653,491],{}," holds 20,000,000 THB. An end customer with ",[219,656,657],{},"no real balance"," on your site submits a stream of withdrawals — often ",[380,660,661],{},"structured"," or \"salami\" style: many small requests of 1,000 THB or 10,000 THB, sized to look unremarkable. Because each request is correctly signed and your ",[234,664,491],{}," still has funds, UnknownPay keeps approving them and each returns ",[234,667,668],{},"withdrawal.success",". UnknownPay never sees that the customer was not entitled — it only ever saw a funded ",[234,671,491],{},". The ",[234,674,491],{}," drains, and that is real money that has left your account. Only your pre-submission validation can stop this; UnknownPay's approval against the ",[234,677,491],{}," cannot.",[215,680,681,684,685,688,689,691],{},[219,682,683],{},"Allocation of liability."," To the extent permitted by applicable law, UnknownPay is ",[219,686,687],{},"not liable"," for losses, shortfalls, or a drained ",[234,690,491],{}," arising from causes that originate on the merchant side, including but not limited to:",[259,693,694,700,706,712,727],{},[262,695,696,699],{},[219,697,698],{},"Merchant negligence"," — failing to validate an end customer's entitlement or balance before submitting a payout.",[262,701,702,705],{},[219,703,704],{},"Lax or insecure integration"," — a loose, misconfigured, or unmonitored integration that lets unauthorised or unvalidated requests through.",[262,707,708,711],{},[219,709,710],{},"Compromise of your systems"," — your platform, servers, or staff accounts being hacked or misused.",[262,713,714,717,718,720,721,723,724,726],{},[219,715,716],{},"Compromised credentials"," — ",[234,719,609],{},", ",[234,722,589],{},", or ",[234,725,593],{}," secrets that are leaked, shared, stolen, or misused.",[262,728,729,732],{},[219,730,731],{},"Fraud originating on the merchant side"," — fraudulent, collusive, or unauthorised requests submitted through your integration.",[215,734,735,736,739,740,742,743,745,746,749],{},"Each of the above is the ",[219,737,738],{},"merchant's responsibility",", and the resulting loss is borne by the merchant. A payout that UnknownPay approved against a funded ",[234,741,491],{}," does ",[219,744,487],{}," transfer that risk to UnknownPay. Where a loss arises in connection with your credentials, integration, systems, or end-customer validation, you bear the burden of demonstrating that it arose ",[219,747,748],{},"solely"," from UnknownPay's own act.",[215,751,752,753,755,756,758,759,761,762,765,766,768,769,771,772,774,775,778],{},"You may ",[219,754,487],{}," rely on an approval, a ",[234,757,483],{}," status, or a ",[234,760,668],{}," webhook as validation of an end customer or of the underlying transaction — UnknownPay makes no such representation. Any monitoring, screening, or fraud detection that UnknownPay performs is undertaken at its ",[219,763,764],{},"sole discretion"," for its own risk management; it is ",[219,767,487],{}," a duty owed to you, creates no warranty, and a failure to detect or prevent any pattern or breach does not create liability for UnknownPay or shift the allocation set out above. UnknownPay's approval or processing of any request, or its not acting on a pattern, does ",[219,770,487],{}," waive these terms. A payout that reaches ",[234,773,483],{}," is final and irreversible on UnknownPay's side; UnknownPay is under ",[219,776,777],{},"no obligation"," to reverse, recover, or refund funds already paid out, and any recovery effort it may undertake is best-effort, without guarantee, and not an admission of liability. This allocation of liability survives suspension, closure, and termination of your account.",[215,780,781,784,785,787,788,791,792,720,796,799],{},[219,782,783],{},"Our response to abuse."," Where UnknownPay detects such patterns — for example structured \"salami\" payout traffic, a sudden change in withdrawal behaviour, a suspected credential or ",[234,786,593],{}," secret compromise, or any other breach of these terms — it reserves the right to ",[219,789,790],{},"suspend or restrict your account",", hold or decline in-flight withdrawals, and, per ",[247,793,795],{"href":794},"#account-suspension","Account suspension",[219,797,798],{},"freeze assets pending investigation",". These measures are protective, are taken in good faith, do not by themselves constitute acceptance of liability by UnknownPay, do not transfer to UnknownPay your liability for activity that has already occurred, and, to the extent permitted by applicable law, shall not give rise to any claim against UnknownPay.",[251,801,795],{"id":802},"account-suspension",[215,804,805,806,809],{},"If your payment-gateway account is suspended and an investigation finds that the cause originated from your shop, UnknownPay reserves the right to ",[219,807,808],{},"permanently close the shop and freeze all assets"," for further investigation.",[251,811,813],{"id":812},"bank-risk-control","Bank risk control",[215,815,816,817,820],{},"Bank-side risk control is ",[219,818,819],{},"handled by the UnknownPay team"," — you do not manage banking relationships or bank risk directly.",[251,822,824],{"id":823},"how-deposits-withdrawals-are-confirmed","How deposits & withdrawals are confirmed",[215,826,827,828,831,832,835,836,838,839,841,842,844,845,404,847,356],{},"The ",[219,829,830],{},"webhook is the source of truth"," for the final status of both deposits and withdrawals. Confirm payment to your end customer on the webhook event (e.g. ",[234,833,834],{},"deposit.success"," \u002F ",[234,837,668],{},"), ",[219,840,487],{}," on the synchronous ",[234,843,619],{}," API response. See ",[247,846,126],{"href":133},[247,848,141],{"href":142},{"title":850,"searchDepth":851,"depth":852,"links":853},"",1,2,[854,855,856,857,858,859,860,861,862],{"id":253,"depth":852,"text":254},{"id":297,"depth":852,"text":298},{"id":364,"depth":852,"text":365},{"id":428,"depth":852,"text":429},{"id":447,"depth":852,"text":448},{"id":471,"depth":852,"text":472},{"id":802,"depth":852,"text":795},{"id":812,"depth":852,"text":813},{"id":823,"depth":852,"text":824},"How your balance is settled back to you (THB \u002F USDT), transaction limits, service hours, supported merchants, and acceptable use.","md",{},{"icon":22},{"title":27,"description":863},"9-pPaPYPlrP5NEY5WxlNOiCwpe92OsFafdn44dKJ2UM",[870,872],{"title":16,"path":17,"stem":18,"description":871,"icon":19,"children":-1},"Make your first end-to-end deposit in the sandbox with a test key",{"title":37,"path":38,"stem":39,"description":873,"icon":40,"children":-1},"Every S2S request is signed with HMAC-SHA256 using your API key id and secret — a bare API key is never accepted",1786869825154]