WALLET & SECURITY

Understand your wallet before you collect.

Funds flow, recovery material and payment verification are separate parts of a crypto checkout. Here is how the current MochiPay setup works.

Customer funds

Customers send cryptocurrency on-chain to the receiving address assigned to their payment order. It belongs to the merchant's configured HD wallet. Customer receipts do not first enter a pooled platform payout balance.

Your MochiPay service subscription is a separate payment to the platform.

Recovery material

The current HD setup generates the recovery phrase on the server, displays it during creation and stores it encrypted in the configured database. The application has decryption capability for its wallet functions.

This is not an address-only or client-only key-storage model. Direct-to-wallet payment does not imply that recovery material is inaccessible to the platform application.

What you control, and what the software does

AreaCurrent behavior
Receiving walletYou create and enable an HD wallet in your account and back up its phrase privately.
Address and payment matchingMochiPay uses the configured wallet and asset/network, assigns the payable amount and watches for matching transfers.
Moving fundsUse a compatible wallet application and verify that its actual receiving address matches the one used by MochiPay. Network fees and token-transfer requirements apply.
Server-side recovery materialStored encrypted; the application can decrypt it. Server permissions, application keys and backups must be protected.
MCP toolsCreate payment requests and query their status. They do not sign wallet transfers or spend funds.
Order fulfillmentYour integration checks a bound authenticated payment result before updating its order or delivering goods. A browser return is not payment proof.

Before your first real payment

  1. Back up the recovery phrase privately during creation. Never send it through support messages or customer fields.
  2. Compare the asset, network and address in your compatible wallet with the actual payment order. Importing a phrase does not guarantee identical derivation paths across wallet apps.
  3. Keep enough native network coin for later transfers. Sending tokens can require ETH, TRX or another network-specific resource.
  4. Start with a small order and send the exact displayed amount. Do not round it or switch networks.
  5. Check the chain transaction, MochiPay order status and your store's order status. Resolve exceptions before delivering goods.

Protect account and integration access

Use a unique password. Keep API secrets on your server and restrict configuration access. Regenerating a secret invalidates integrations that still use the previous one. Support does not need your recovery phrase or private key.

For payment questions, share a sanitized order reference and transaction hash through the official help channels. Do not include secrets, full configuration files or recovery material.

This page describes the current model. It is not a third-party security audit or a promise that blockchain transfers can be reversed.