Security

Payment security

Unsu uses server-authoritative invoice state and authenticated status checks to keep payment decisions away from untrusted browser code.

API credentials

API keys are generated in the merchant’s browser and stored by Unsu only as SHA-256 hashes. The plaintext key cannot be recovered. A lost key must be rotated, which invalidates the previous key.

Merchant wallet addresses

Merchants supply their receiving wallet addresses when creating an invoice. The invoice snapshots those addresses so checkout does not depend on mutable browser input.

Payment confirmation

Report a security issue

Send a concise technical report to [email protected]. Include the affected endpoint, reproduction details, and impact without including customer payment data.