FAQ
Frequently asked questions
How non-custodial payments work, and what happens when the chain doesn't behave. Grouped by what you're probably wondering.
Custody & funds
Who holds the money
Is LevinGate custodial? Who holds the funds?
Non-custodial, always. Customers pay to wallet addresses that YOU control. LevinGate never stores private keys or seed phrases, never signs transactions, and never sweeps or holds funds at any point. If LevinGate disappeared tomorrow, your money would be exactly where it always lands — your wallet.
If LevinGate can't move funds, how would a refund work?
Refunds are yours to make, directly from your wallet — that's what non-custodial means. Overpayments and wrong-asset transfers are recorded with the exact amount, tx hash, and sending address, so you have everything needed to refund precisely (or deliberately not).
Do you ever see or store my seed phrase?
No. There is no point in the product — wallet connection, address verification, settlement — where a seed phrase is requested, transmitted, or stored. Address verification on EVM chains uses a message signature challenge, not key material.
Payments & matching
When the chain behaves — and when it doesn't
How is a payment confirmed?
A payment is marked PAID only after the network confirmations configured for that chain are reached (e.g. 15 on BNB Smart Chain, 20 on TRON). Before that, the checkout shows live detection and confirmation progress — DETECTED means seen in a block, CONFIRMING means accumulating finality.
What happens if a customer sends the wrong token or uses the wrong network?
The matching engine detects the transfer on-chain and records it — flagged as wrong-asset or wrong-network — but it is never credited to the invoice. You see exactly what arrived (tx hash, amount, sending address) and handle recovery directly with your customer. Silent miscrediting is impossible by design.
What if a customer pays after the invoice expires, or pays the wrong amount?
Late payments after expiry are recorded with a late-payment flag (the invoice stays EXPIRED — no surprise state changes). Underpayments and overpayments are measured against your per-store tolerance and policy settings: within tolerance auto-acknowledges, beyond it flags for manual review.
Can a chain reorganization create a fake payment?
No. If a reorg walks back a transaction, the payment state walks back with it honestly, and a reconciliation record is created instead of a phantom PAID. You'd see the reorg flagged with severity, not discover it later.
How does pricing work at checkout?
The fiat→crypto quote is locked for a window when checkout opens and recorded on the invoice. The customer pays the locked amount; what they pay is what you invoiced — no moving-target pricing.
Integration
Wiring it into your stack
Can I use my existing website and stack?
Yes. Create invoices over REST from any backend, redirect customers to the hosted checkout (optionally scoped to your store's branding), and receive signed webhooks — no frontend SDK required. Multi-store support lets one account serve several websites with separate branding and payment methods.
How do I know a webhook really came from LevinGate?
Every webhook is signed with HMAC-SHA256 over a timestamp and the raw body, sent in the X-LevinPay-Signature header (t=<timestamp>,v1=<signature>). Verify it with your endpoint's signing secret before trusting a payload — delivery retries with exponential backoff until you acknowledge.
Do you support testnets?
Yes — every merchant account gets test/live API key isolation, and the platform runs against testnet chains (BNB Smart Chain testnet, TRON Nile, Sepolia, Bitcoin testnet4, Litecoin testnet) so you can integrate risk-free before enabling mainnet.
Which chains and assets are supported?
BNB Smart Chain, TRON, Ethereum, Bitcoin and Litecoin, with native assets and major tokens (e.g. USDT on BSC/TRON, USDC on Ethereum). Tokens are identified by their on-chain contract address — never by symbol — so fake tokens can't impersonate real ones.
Is there a request I can't retry safely?
Invoice creation (and other writes) accept an idempotency key — a retried request with the same key returns the original invoice instead of creating a duplicate. List endpoints use cursor pagination so results stay stable while you page.
Account security
Your account, hardened
What about security on my account?
TOTP two-factor authentication (with a QR code for any authenticator app), sessions that can be revoked server-side, API keys displayed only once at creation with per-key test/live mode, and an append-only audit trail for security-relevant actions.
Who on the platform can see or change my configuration?
Platform operators have tooling for chain-level and merchant-level controls (network activation, per-merchant asset availability), and every operator action is written to the audit log with their identity. Sensitive attestations — like verifying a token contract — require a written comment that's stored permanently.
What happens if I lose my 2FA device?
Contact support from your account email to start identity verification and a session reset. The 2FA secret is per-account and can be re-enrolled once identity is verified — the same process a bank runs, minus the custody.
More questions? Contact us — or ask about a specific integration when you create an account.

