Merchant checkout
Accept payment without inheriting a public list of every payer.
Status: design. XEROPAY is being built. These pages describe intended behaviour. Nothing here is claimed as live mainnet. Details can change. See What's live.
A customer can pay from a shielded note or a one-time stealth address. You receive confirmation. You do not inherit an explorer-shaped customer graph.
Session flow
- Quote — amount, asset, expiry. Unpaid quotes do not linger.
- Settle — customer pays from a note or a fresh stealth address.
- Confirm — webhook fires settled. Refunds are new notes, not a reverse of a public tx.
What merchants still get
Paid / failed / expired. Optional proof of payment for disputes. Not a worldwide feed of who shops with you.
