Developers
Cards, top-ups and alerts, from your own code.
A simple REST API and a TypeScript SDK for everything you can do in the app. Automate ad accounts, subscriptions and team spending.
- REST + JSON
- TypeScript SDK
- Signed webhooks
import { Veilo } from "@veilo/sdk";
const veilo = new Veilo({ apiKey: process.env.VEILO_API_KEY });
// See the price, then order a card
const order = await veilo.orders.issue({
productId: "prd_onyx_visa",
load: "100",
coinId: "usdt",
chain: "TRX",
});
console.log(order.payment.address);Start in three steps
- Step 1Create a keyIn Developers, pick a name and what the key can do.Get an API key
- Step 2Make your first callList your cards or products with one request.
- Step 3Listen for eventsAdd a webhook endpoint and verify each signature.
What you can do
The same things you can do in the app, and nothing that bypasses your security settings.
Issue cardsOrder a new Visa or Mastercard and get it ready in minutes.
Top upAdd money to any card, with a quote before you pay.
Card detailsRead number, expiry and CVV, only with the right permission.
Freeze, unfreeze, cancelControl every card from your own tools.
TransactionsEvery purchase, refund and fee, filterable by card and date.
3D SecureApprove or decline online payments from your code.
PayoutsAsk for a cancelled card's balance to be sent back to you.
WebhooksSigned events the moment something happens.
Webhooks
Know the moment something happens
We send a signed POST to your endpoint for each event, and retry if your server is down. Check every delivery in your delivery log.
- order.paid
- order.completed
- order.needs_review
- order.expired
- card.issued
- card.status_changed
- card.topped_up
- transaction.created
- threeds.requested
- payout.updated
- limit.breached
import { parseWebhook } from "@veilo/sdk";
const event = await parseWebhook(
rawBody,
req.headers["veilo-signature"],
process.env.VEILO_WEBHOOK_SECRET,
);
if (event.type === "threeds.requested") { /* … */ }Safe by design
Keys only do what you allow. Card details and money movements need their own permission.
Scoped keysGive each key only what it needs: read only, or full access.
IP allowlistLock a key to your servers' addresses.
Expiring keysSet keys to expire, and revoke them any time.
Safe retriesIdempotency keys make repeated requests harmless.
Every endpoint, with examples
Requests, responses and errors, with a console to try calls with your own key.