Skip to content

Settings

Account → Settings holds everything about your account that is not a transaction. Every signed-in user can reach their own profile here, whatever else their role allows; the rest of the page is permissioned.

Your legal name, trading name, what you sell, and your verification documents.

This is not administrative box-ticking. Live payments are gated on it: an account with verification outstanding gets kyc_required on every live request, and a description of your business that does not match what you actually sell is the sort of thing that surfaces at the worst moment, usually during a dispute or a risk review.

If your business changes — new products, a new channel, a materially different average transaction — tell us. Your limits and risk profile are set against what we understand you to do.

Where your money goes. A bank account or a mobile money wallet in your business’s name.

Changing it is a high-value action. Keep the permission for it on a short list, and expect to re-verify when you change it — an unverified change of destination is exactly the shape of a successful account takeover, so the friction is the point.

You can choose, per transaction, whether your business or the customer carries the fee — if your account permits it.

  • Merchant bears — the customer pays the amount you asked for; your balance receives it minus the fee. The fee is a cost of sale.
  • Customer bears — the customer is charged more than your price; you receive your price.

The transaction shows all of it: amount, customer_amount and merchant_amount are three separate numbers precisely so this is never ambiguous. See Transactions.

Customer-borne fees are visible to the customer at payment time. Decide this deliberately rather than leaving it on a default — it is a pricing decision, and the abandonment it can cause is larger than the fee.

Which payment methods are enabled: mobile money, bank, card. Card typically requires additional verification, because card scheme rules are stricter than wallet rules.

A channel that is not enabled returns capability_disabled rather than failing mysteriously, so if your integration is being refused on one method and not another, check here first.

Worth turning on, in order of value:

  1. Two-factor authentication, for everyone with access — not only administrators. The portal can move money.
  2. IP allowlisting on API keys — see API keys. The highest-value control on the account, and a one-minute change.
  3. A second administrator, so one lost phone is not an outage. See Your team.

Which emails your team receives, and who receives them.

Two are worth routing to a person rather than a shared inbox nobody reads: disputes, because they carry a deadline that loses by default, and webhook endpoint failures, because by the time deliveries are disabled your systems have been out of step for a while. See Disputes and Webhooks.

Ask us. There is money to settle, a notice period, and records we are required to retain whatever either of us would prefer — so this is a conversation, not a button. Write to [email protected].