InsPay Merchant API
Version 1.1 · 11 October 2026
Create bank-transfer deposits and withdrawals, read balances, list banks, and register players for JPY KYC. Every call is a POST with a JSON body from your server.
Only COMPLETED means money moved. SUCCESS means InsPay accepted the order. It does not mean the payer has paid.
Sandbox and production each have their own API key, secret key, and IP allow list. Keys in this documentation are placeholders: YOUR_API_KEY and YOUR_SECRET_KEY.
Coming soonmarks a change that is still rolling out. Integrations built to today’s behaviour keep working.
Before you call the API
InsPay onboarding gives you, per environment:
- an API key and a secret key
- an allow-listed set of server IPs
- a KYC channel value, until Coming soonmakes
gatewayoptional
Then:
- Implement signing and check it against the worked example.
- Send JPY amounts as whole yen.
- Register a JPY player with KYC before their first deposit.
- Reply
SUCCESSfrom your callback URL. - If you miss a callback, poll transactions.
- On a timeout or
5xxfrom deposit or withdraw, query the transaction before you retry.
Conventions
- Every endpoint is
POSTwithContent-Type: application/json. - Request and response fields are camelCase.
- Callbacks use snake_case. The balance response uses snake_case too.
- Send the exact body you signed. Pretty-printed JSON will not match the signature.
Where to go next
HMAC-SHA256 over canonical JSON, with curl, Node.js, and Python.
Signing requestsOpen a JPY bank transfer and send the payer to the payment page.
Create a depositPay a bank account. The amount plus fee is held at creation.
Create a withdrawalFinal COMPLETED and FAILED notices, and how to acknowledge them.