Skip to main content

CHIP Send API

The CHIP Send API enables merchants to send funds programmatically via a REST API and to register recipient bank accounts for payouts. All endpoints share a single base URL and a single authentication scheme. This page covers everything required to make a successful request.

Endpoints

The base URL must match the merchant’s environment: The operation path from the API reference (for example /send/accounts or /send/send_instructions) is appended to the base URL.

Prerequisites

Before integration begins, a CHIP Send account must be created for the merchant by the CHIP admin team. To obtain credentials, the merchant’s CHIP Account Manager must be contacted with the following information:
  1. A primary email address.
  2. The email addresses of every required approver. If two approvals are required, both email addresses must be provided.

Credentials

Two pieces of information are issued to the merchant: The API Key and the api_key value used inside the checksum string are the same value. The API Secret is never transmitted in any request. It only ever lives on the merchant’s server and is used to compute the checksum described below. Both the API Key and the API Secret are available to the merchant in the CHIP Control → Settings → Applications page of the merchant portal.

How authentication works

Every request to the CHIP Send API must include three headers: The epoch value must be within 30 seconds of the server’s clock. If it is too old or too far in the future, the request is rejected as Unauthorized. The merchant’s server clock must therefore be synchronised (for example via NTP).

How to compute the checksum

The signing string is formed by concatenating the epoch value and the API Key with no separator, in that order:
For example, with epoch = 1689826456 and API Key = e0645c9e-fcf2-4f29-a327-202f7ed3d969:
The checksum is then computed as:
Given API Secret = a118729e-4243-4145-83b3-0b8cb213fe8e, the checksum for the example signing string above is:
This expected value can be used to verify the implementation before any real request is sent.

A complete request

The following curl example computes the epoch and checksum, then sends a request end-to-end:
A 200 OK response confirms that authentication is working correctly. For other responses, see Troubleshooting below.

Language examples

The same computation in four common languages:

Troubleshooting

Basic integration flow

A complete payout consists of four steps:
  1. The Accounts API is called to check the convertible balance.
  2. The Increase Send Limit API is called to allocate balance for payouts.
  3. The Add Bank Account API is called to register a recipient.
  4. The Create Send Instruction API is called to send funds.
A walkthrough is provided in Test Integration.

Approving CHIP Send Budget Allocation requests

Every approver receives an email when a budget-allocation request requires approval. Approval is performed by clicking the Approve button in the email. Once all required approvers have approved, the new balance is reflected in the Accounts API response. The token used in the Authorization header is the API Key mentioned in the Credentials section above.