generated: '2026-08-17' method: searched source: https://docs.fipto.com/docs/introduction also: https://docs.fipto.com/docs/api-authentication, https://docs.fipto.com/docs/postman-guide, openapi/fipto-customer-api-openapi.yml note: >- Fipto runs a real, fully separate demo environment with its own hosts, its own webhook signing key and its own webhook source IPs, plus a first-class payin simulation endpoint in the API. It is NOT self-serve: access is granted by Fipto after a request, not by generating a test key. Every value below is published by Fipto verbatim; nothing here is invented. environments: - mode: demo api_host: https://api.demo.fipto.tech platform: https://demo.fipto.tech purpose: Test both the platform interface and the API before KYB. access: Request at https://www.fipto.com/demo and supply an RSA public key. - mode: production api_host: https://api.fipto.app platform: https://fipto.app/ purpose: Live money movement. access: Issued after successful KYB verification. key_separation: style: separate-host-and-credential prefixes: [] note: >- There are no test-vs-live key PREFIXES (Fipto has no API keys — auth is an RSA signature keyed by an API user UUID). Separation is by host and by credential: a demo API user UUID and key pair only work against api.demo.fipto.tech. The environment is therefore never ambiguous from the URL, but also never switchable by swapping a key prefix. warning_from_docs: >- "For your safety, do not use any key that you will or already use in production environment." (Postman setup guide) simulation: - name: Simulate a payin kind: api-operation operation: simulatePayin method: POST path: /companies/{company_id}/wallets/{wallet_id}/payin-simulation environments: [demo] response: 204 behaviour: >- Generates a payin on the demo environment. May take up to 1 minute to appear in the transactions list. By default targets the first wallet details created within the wallet. note: The only fixture/trigger tool Fipto ships. It is a documented, tagged operation in the public contract ("Payin Simulation"), not a hidden endpoint. test_values: note: >- Fipto publishes NO magic test card numbers, test IBANs, test blockchain addresses or test beneficiaries. Demo data is generated by the simulation endpoint against the caller's own demo wallets. The IBANs and addresses that appear in the webhook documentation examples are documentation samples (e.g. GB90MOCK00000003779553, FR93MOCK00000003340671) and are marked MOCK by Fipto, not published as usable test values. documented_samples: - {kind: iban, value: 'GB90MOCK00000003779553', context: webhook payin example (source)} - {kind: iban, value: 'FR93MOCK00000003340671', context: webhook payin example (destination)} - {kind: bic, value: MOCKGB21, context: webhook payin example} webhooks_in_demo: signing_public_key_published: true demo_source_ips: [3.77.91.94, 3.73.145.20, 3.120.72.252] note: Fipto publishes a distinct demo webhook verification public key, so a consumer can build and verify the full webhook path end to end before going live. docs: https://docs.fipto.com/docs/webhooks tooling: - kind: postman-collection name: Fipto API — Demo environment url: https://www.postman.com/galactic-meadow-917828/workspace/fipto-api-demo-environment/collection/24959087-42b9da95-ca00-4b9a-89cc-52d84d432d5f environment_template: https://www.postman.com/galactic-meadow-917828/workspace/fipto-api-demo-environment/environment/24959087-10e65c39-2571-4a8d-898d-62ba44a35756 note: >- Pre-request script builds the HTTP signature header. baseUrl and environment are pre-filled; the developer supplies company-id, key-id and private-key. docs: https://docs.fipto.com/docs/postman-guide test_clock: false self_serve: false production_parity_claimed: true production_parity_source: https://www.fipto.com/crypto-brokers