Gateway Admin
Merchants
—
Paid payments
—
Open internal payments
—
Open withdrawals
—
Watcher health
Checking…
—
Financial overview
| Received | — USDT |
| Locked for withdrawal | — USDT |
| Webhook failures | — |
| Chain events | — |
| Receiving addresses | — |
| Open sweeps | — |
| Treasury wallets | — |
| Payment links total | — |
| Payment links active | — |
| Payment links paid | — |
Mainnet readiness
Production checks for deposits, custody, observers, gas/resources and guarded execution.
Custody safety: this panel never displays private keys or signing secrets. Signing stays isolated in the Cloudflare signer and execution remains policy-gated.
Add public receiving address
Private keys are never entered here. signer_ref is only an opaque reference used by the isolated signer service.
Receiving address pool
Allocator prefers PRIMARY → FILLING → STANDBY and tracks exact-amount reservations.
Mainnet wallet setup
Registered public receiving and treasury addresses. Automatic transfers become available after signing access and network setup are verified.
Loading wallet setup…
Verify wallet ownership
Sign a one-time message with the selected wallet. Never enter or paste a private key or seed phrase here.
Select a registered wallet, then connect.
No active challenge.
Configure treasury public wallet
Public address + signer reference only. No signing key is stored in this app.
Treasury wallets
Sweep queue
Full source balance onlySigning safety: the isolated signer service exists, but broadcast remains disabled until verified mainnet keys/contracts are configured and the readiness gates pass.
Signer service
—
Signing enabled
—
Keys configured
—
Pending jobs
—
Mainnet signer guard
Production policy boundary only. It cannot load keys, sign transactions or broadcast funds.
Loading mainnet signer readiness…
Cloudflare custody cutover
Compares the external non-exportable custody wallets with the currently registered mainnet inventory. No wallet address is changed from this panel.
Loading Cloudflare split-key custody…
Mainnet activation approvals
OWNER + 2FA approvals are audited. Approval alone never enables signing without all other gates.
Loading activation state…
Mainnet execution queue
Isolated from the mainnet signer. Jobs appear only after all execution gates and guard preflight pass.
Signing jobs
Private keys are isolated from this panel. Broadcast confirmation is reconciled separately.
Gas / resource snapshots
Latest observed native and token balances from the signer service.
Current mode: mainnet control plane is live. The isolated signer and executor remain fail-closed until OWNER + 2FA activation approvals; customer deposits are controlled by a separate readiness gate.
All internal payments
Admin-only internal statesPayment Links
One-time merchant-created payment requests. PAID links are permanently consumed.
Withdrawals
Withdrawal ledger audit
Lock, release, completion and native network-resource records.
Merchants
Delivery worker
—
Pending / retrying
—
Delivered
—
Dead / terminal
—
Webhook deliveries
Persistent retry queue · signed events · redirects disabled · public-IP destinations only.
Email provider
—
Provider configured
—
Sent
—
Failed
—
Security email deliveries
Recipient addresses are masked; OTP values and provider secrets are never shown.
Payout whitelist rule: address activation requires authenticator verification plus successful email OTP verification. If the provider is not configured, the address remains non-active.
Active whitelisted
—
Pending verification
—
Blocked attempts
—
Whitelist-bound withdrawals
—
Payout address whitelist
Verified state, merchant ownership, last use and lifecycle.
Withdrawal → whitelist binding
Immutable snapshot of the payout address used when a withdrawal was requested.
Security events
Whitelist creation, activation, disablement and blocked payout attempts.
Open exceptions
—
Late payments
—
Partial payments
—
Overpaid
—
Unmatched / other
—
Chain reconciliation exceptions
Never auto-credit mismatched or late payments. OWNER may resolve a linked exact late payment through the normal PAID credit flow.
Integrity
—
Transactions
—
Postings
—
Accounts
—
Double-entry reconciliation
Every financial transaction must net to zero across postings. Merchant available balances are reconciled against the legacy ledger during migration.
Loading ledger integrity…
Unbalanced transactions
Merchant balance mismatches
Tracked buckets
—
Blocked in 24h
—
Top scope
—
Rate-limit buckets
IP, email and token identities are one-way hashed before storage. Raw identifiers are never shown here.
Blocked requests
Recent server-side rate-limit blocks from sensitive authentication, OTP and public payment-link routes.
Open incidents
—
Critical
—
High
—
Resolved
—
System incidents
Background monitor detects service outages, stuck signing jobs, stale withdrawals/sweeps, ledger mismatch, webhook dead letters, reconciliation backlog and abuse spikes.
Admin team
Workers are VIEWER-only.
Audit trail
Two-factor authentication
CHECKINGRequired for OWNER controls. Until 2FA is enabled and verified, network changes, treasury/address mutations, sweeps and team-management actions are blocked by the API.
Scan QR code
Google Authenticator, Microsoft Authenticator, Authy or any TOTP app.
QR scan na ho to secret manually add karo. QR/secret ko kisi ke saath share mat karo.
2FA enabled. OWNER mutations require a 2FA-verified login session.
Change password
Access model
OWNER can change emergency network states and manage view-only workers only with a 2FA-verified session. VIEWER accounts can inspect monitoring data only. No admin role can access signing keys from this interface.