Navigate
Stack Methods Cabinet Go live Contact API documentation

Nested HMAC · idempotent creates · signed webhooks

Money movement as a contract.

SPQR opens and services merchant IDs for PayIns and PayOuts. One signed API, local methods we underwrite, reserved balances, and a cabinet your ops team can actually run.

Uptime posture
0%
Ops coverage
24/7
Signature
HMAC-SHA256
Contact
Telegram
The stack

Not a brochure of products. A merchant ID we open and run.

You integrate once. We issue the MID, accept the signed contract, keep gross, net, and reserved outflow honest, and operate the desk that finance and engineering both use.

  1. 01 · MID

    We open the merchant ID

    Commercial setup, credentials, and a live account on rails we service — not a pass-through to someone else’s stack.

  2. 02 · API

    One PayIn / PayOut contract

    Nested HMAC-SHA256, timestamps, and idempotency keys. Secrets stay on your backend.

  3. 03 · Ledger

    Balances you can defend

    Pay-in, pay-out, and reserved outflow stay reconcilable instead of “dashboard math”.

  4. 04 · Desk

    We operate the MID

    Statuses, limits, incidents, and settlement — one cabinet and a 24/7 ops channel.

Methods

Local rails. Our MIDs.

Customers pay the way their market already pays. You keep one status machine, one webhook, one settlement view — on accounts we issue and service.

Lifecycle

NEW → PENDING → terminal

Every operation is a versioned state, not a screenshot. Webhooks retry until the MID is settled or declined.

NEW PENDING SUCCEEDED FAILED
PayIn

Collect

Return the customer action the method needs — redirect, QR, or instructions — then wait for the signed callback.

PayOut

Disburse

Reserve outflow first. Release or capture against the same natural key the ledger already knows.

Cabinet

The same surface as production ops.

SMerchant cabinet Production
Pay-in184.2K
Pay-out42.6K
Reserved8.9K
create-payin.jssigned
const payment = await spqr.payments.create({
  merchant: "acme_my",
  amount: 12500,
  currency: "MYR",
  payment_method: "duitnowqr"
});
Go live

Four beats. No portal maze.

02

MID

We open the merchant ID and issue cabinet access after commercial setup.

03

Secrets

HMAC keys stay in your backend. First PayIn from staging.

04

Live

Your MID is live: local methods, signed webhooks, 24/7 desk on the same channel.

Operations

The desk is on Telegram.

MID onboarding, incidents, and settlement — one handle, no ticket queue as the front door.

@spqr_operations
Opening Telegram @spqr_operations