Reseller API
HTTP API to request Flash token delivery from your bot or site. After payment to the shop, tokens go to the recipient wallet.
There is no self-signup. An admin creates an API key and sends it to you privately.
Base URL
All reseller routes live under /api/v1 on the shop domain.
https://flashcryptoshop.com/api/v1
Access
Every method except GET /api/v1 needs a key. Header Authorization: Bearer fcs_… or X-Api-Key: fcs_…. CORS: * for GET, POST, OPTIONS. Bodies are JSON with Content-Type: application/json. Catalog prices are whatever is set on the key (discount_percent and wholesaleTiers). Authorization: Bearer fcs_…
How a sale works
- GET catalog — product, flash_token, minTokens, wholesaleTiers, payMethods.
- POST orders with the customer address and token_amount. pay_currency may be set immediately.
- Show checkout on your side. Pay the shop via wallet+amount (on-chain) or invoice_url.
- TON / USDT-on-TON: memo = order_id or the payment will not credit.
- POST …/check after payment. Tokens go to address. Then GET the order or wait for the webhook.
Common errors
Error body is always { "error": "…" }. Codes below can appear on any authenticated method.
401 Missing or invalid API key — Missing key, not fcs_…, or wrong secret.
401 Invalid API key — Key hash not found.
403 API key is disabled — Key disabled in admin.
429 Too many requests — Limits: catalog/read 120/min, create and pay/invoice 30/min, check 40/min.
{ "error": "Missing or invalid API key" }Order object
This is the order in create/get/pay/invoice/check (plus invoice_url on create/pay/invoice).
| Field | Type | Req. | Description |
|---|---|---|---|
order_id | string | yes | Order id; also the TON memo. |
status | string | yes | waiting | on_hold | sending | paid | completed | expired | cancelled | send_failed |
product | string | no | trust, metamask, safepal, binance, bybit, okx… |
flash_token | string | no | Catalog id when the product has several flash tokens. |
address | string | yes | Customer delivery address. |
token_amount | number | yes | How many flash tokens to send. |
usd_value | number | yes | Wholesale amount you pay the shop (after key discount). |
retail_usd_value | number | yes | Public shop price before reseller discount. |
discount_percent | number | yes | Key discount, 0 if none. |
pay_currency | string|null | no | Pay method: ton, usdt, bnb, usdt_bsc, eth, usdt_erc20, usdt_base, sol, usdt_sol, trx, usdt_trx, cryptobot, stars, lzt, xrocket. null until selected. |
payment_selected | boolean | yes | Whether pay currency is locked. |
wallet | string|null | no | Shop wallet for on-chain pay. null for invoices. |
amount | number|null | no | Amount to send in pay_currency (TON/USDT/BNB/…). |
amount_stars | number|null | no | Stars amount if pay_currency=stars. |
amount_rub | number|null | no | RUB amount for LZT. |
memo | string | yes | Always order_id. Put in TON / USDT-on-TON payment comment. |
tx_hash | string|null | no | Delivery tx hash after payment. |
send_error | string|null | no | Delivery error text. |
client_order_id | string|null | no | Your sale id if you sent one. |
invoice_url | string|null | no | CryptoBot / Stars / LZT / xRocket URL. |
invoice | object|null | no | Raw invoice payload (pay_url, stars_amount…). |
created_at | string | no | ISO created time. |
Endpoints
GET
/api/v1
API map. No key required.
GET
/api/v1/catalog
Products, flash tokens, packages and wholesale prices for your key.
POST
/api/v1/orders
Create an order. You may pass pay_currency immediately — then the response already has wallet/amount or invoice_url.
GET
/api/v1/orders
Last 50 orders for this key, newest first.
GET
/api/v1/orders/{order_id}
One order. {order_id} like FT-…. Another key’s order is not returned.
POST
/api/v1/orders/{order_id}/pay
Select or change pay currency while the order is still payable.
POST
/api/v1/orders/{order_id}/invoice
Re-issue the invoice URL. No body. pay_currency must already be cryptobot, stars, lzt or xrocket.
POST
/api/v1/orders/{order_id}/check
Check chain/invoice payment and trigger delivery. No body or query.
Endpoints in detail
GET
/api/v1
no auth
API map. No key required.
Query
none
JSON body
none
Success 200
JSON with version, docs, auth and path list.
Errors
GET
/api/v1/catalog
Products, flash tokens, packages and wholesale prices for your key.
Query
none
JSON body
none
Success 200
discount_percent, products[], payMethods[]. Each flash token has id, addressType, minTokens, tiers and wholesaleTiers (price for this key).
Response example
{
"discount_percent": 25,
"products": [
{
"productKey": "trust",
"slug": "trust",
"name": "Trust Wallet USDT",
"shortName": "Trust Wallet",
"network": "BNB Smart Chain",
"addressType": "bsc",
"placeholder": "0x...",
"needsFlash": true,
"flashTokens": [
{
"id": "usdt_sol_2",
"label": "USDT SOL",
"ticker": "USDT",
"addressType": "solana",
"networkShort": "Solana",
"chain": "solana",
"minTokens": 500,
"minUsd": 7.5,
"wholesaleMinUsd": 5.625,
"tiers": [{ "tokenAmount": 1000, "priceUsd": 15, "label": null }],
"wholesaleTiers": [{ "tokenAmount": 1000, "priceUsd": 11.25, "label": null }],
"percentBands": null,
"unavailable": false
}
]
}
],
"payMethods": [
{ "id": "ton", "label": "TON", "network": "TON", "invoice": false },
{ "id": "cryptobot", "label": "CryptoBot", "network": "CryptoBot", "invoice": true }
]
}Errors
401 Missing or invalid API key
403 API key is disabled
429 Too many requests
POST
/api/v1/orders
Create an order. You may pass pay_currency immediately — then the response already has wallet/amount or invoice_url.
Query
none
JSON body
| Field | Type | Req. | Description |
|---|---|---|---|
product | string | yes | Catalog key: trust, metamask, safepal, binance, bybit, okx… |
address | string | yes | Customer wallet matching product/token addressType. Alias: bsc_address. |
token_amount | number | yes | Integer token count, at least catalog minTokens. |
flash_token | string | no | Required when needsFlash=true (Trust / MetaMask / SafePal). id from catalog.flashTokens. |
pay_currency | string | no | Lock payment now: ton, usdt, bnb, usdt_bsc, eth, usdt_erc20, usdt_base, sol, usdt_sol, trx, usdt_trx, cryptobot, stars, lzt, xrocket. If omitted, status waiting without wallet — then POST …/pay. |
client_order_id | string | no | Your unique id, max 64 chars. Reuse on the same key → 409. |
callback_url | string | no | HTTPS webhook for this order only. Else the key default is used. |
lang | string | no | ru | en — notification language if any. |
amount | number | no | Instead of token_amount: public-shop USD amount (rarely needed). |
Success 201
Order object. Invoice methods include invoice_url. For TON/USDT-on-TON pay wallet with memo=order_id.
Response example
{
"order_id": "FT-XXXXEXAMPLE",
"status": "waiting",
"product": "trust",
"flash_token": "usdt_sol_2",
"address": "CLIENT_WALLET",
"token_amount": 1000,
"usd_value": 11.25,
"retail_usd_value": 15,
"discount_percent": 25,
"pay_currency": "ton",
"pay_network": "ton",
"payment_selected": true,
"wallet": "UQ…",
"amount": 7.5,
"amount_stars": null,
"amount_rub": null,
"memo": "FT-XXXXEXAMPLE",
"tx_hash": null,
"send_error": null,
"client_order_id": "my-sale-1",
"created_at": "2026-09-22T00:00:00.000Z",
"invoice_url": null,
"invoice": null
}Errors
400 Invalid flash_token
400 Invalid BSC address / Invalid Solana address / Invalid TON address / Invalid Tron address
400 Minimum order is N tokens
400 Invalid or disabled pay_currency — The order is already created; body still has order_id.
403 Token temporarily unavailable
409 client_order_id already used — Body includes the existing order_id.
429 Too many requests
GET
/api/v1/orders
Last 50 orders for this key, newest first.
Query
none
JSON body
none
Success 200
{ "orders": [ …order object ] }. No query params, no pagination.
Errors
401 Missing or invalid API key
429 Too many requests
GET
/api/v1/orders/{order_id}
One order. {order_id} like FT-…. Another key’s order is not returned.
Query
none
JSON body
none
Success 200
Bare order object.
Response example
{
"order_id": "FT-XXXXEXAMPLE",
"status": "waiting",
"product": "trust",
"flash_token": "usdt_sol_2",
"address": "CLIENT_WALLET",
"token_amount": 1000,
"usd_value": 11.25,
"retail_usd_value": 15,
"discount_percent": 25,
"pay_currency": "ton",
"pay_network": "ton",
"payment_selected": true,
"wallet": "UQ…",
"amount": 7.5,
"amount_stars": null,
"amount_rub": null,
"memo": "FT-XXXXEXAMPLE",
"tx_hash": null,
"send_error": null,
"client_order_id": "my-sale-1",
"created_at": "2026-09-22T00:00:00.000Z",
"invoice_url": null,
"invoice": null
}Errors
404 Order not found
429 Too many requests
POST
/api/v1/orders/{order_id}/pay
Select or change pay currency while the order is still payable.
Query
none
JSON body
| Field | Type | Req. | Description |
|---|---|---|---|
pay_currency | string | yes | One of: ton, usdt, bnb, usdt_bsc, eth, usdt_erc20, usdt_base, sol, usdt_sol, trx, usdt_trx, cryptobot, stars, lzt, xrocket. Must be enabled in the shop. |
Success 200
Updated order + invoice_url for cryptobot/stars/lzt/xrocket.
Errors
400 Missing pay_currency
400 Invalid or disabled pay_currency
400 Order is not payable
404 Order not found
429 Too many requests
POST
/api/v1/orders/{order_id}/invoice
Re-issue the invoice URL. No body. pay_currency must already be cryptobot, stars, lzt or xrocket.
Query
none
JSON body
none
Success 200
Order + invoice_url + invoice (e.g. { pay_url, stars_amount }).
Errors
400 Order is not payable
400 Select an invoice pay_currency first (cryptobot, stars, lzt, xrocket)
400 Invoice failed / CryptoPay is not configured / …
404 Order not found
POST
/api/v1/orders/{order_id}/check
Check chain/invoice payment and trigger delivery. No body or query.
Query
none
JSON body
none
Success 200
Order object + verification (internal check payload). If paid, tokens go to address and webhook order.paid fires.
Errors
404 Order not found
429 Too many requests
4xx/5xx checker status if unpaid — read order status (waiting / expired).
curl examples
Catalog
curl -s https://flashcryptoshop.com/api/v1/catalog \ -H "Authorization: Bearer fcs_YOUR_KEY"
Create order
curl -s -X POST https://flashcryptoshop.com/api/v1/orders \
-H "Authorization: Bearer fcs_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{
"product": "trust",
"flash_token": "usdt_sol_2",
"token_amount": 1000,
"address": "CLIENT_WALLET_ADDRESS",
"pay_currency": "ton",
"client_order_id": "my-sale-1"
}'List orders
curl -s https://flashcryptoshop.com/api/v1/orders \ -H "Authorization: Bearer fcs_YOUR_KEY"
Get order
curl -s https://flashcryptoshop.com/api/v1/orders/FT-XXXX \ -H "Authorization: Bearer fcs_YOUR_KEY"
Select pay currency
curl -s -X POST https://flashcryptoshop.com/api/v1/orders/FT-XXXX/pay \
-H "Authorization: Bearer fcs_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"pay_currency": "cryptobot"}'Invoice
curl -s -X POST https://flashcryptoshop.com/api/v1/orders/FT-XXXX/invoice \ -H "Authorization: Bearer fcs_YOUR_KEY"
Check payment
curl -s -X POST https://flashcryptoshop.com/api/v1/orders/FT-XXXX/check \ -H "Authorization: Bearer fcs_YOUR_KEY"
Webhook
After a status change the shop POSTs JSON to the order or key callback_url (https). The same order_id+event is not sent twice. 8s timeout.
Headers
| Field | Type | Req. | Description |
|---|---|---|---|
Content-Type | application/json | yes | Body is JSON; signature is over the raw bytes. |
X-Reseller-Signature | hex | yes | HMAC-SHA256(webhook_secret, raw body), hex. |
X-Reseller-Event | string | yes | order.paid | order.send_failed | order.expired |
JSON body
| Field | Type | Req. | Description |
|---|---|---|---|
event | string | yes | order.paid — paid/delivered; order.send_failed — paid but delivery failed; order.expired — slot expired. |
order_id | string | yes | Order id. |
status | string | yes | Current status. |
product | string | no | Product. |
flash_token | string | no | Flash id. |
token_amount | number | no | Token amount. |
usd_value | number | no | Wholesale USD. |
tx_hash | string|null | no | Delivery hash. |
send_error | string|null | no | Delivery error. |
client_order_id | string|null | no | Your id. |
address | string | no | Customer address. |
{
"event": "order.paid",
"order_id": "FT-XXXXEXAMPLE",
"status": "paid",
"product": "trust",
"flash_token": "usdt_sol_2",
"token_amount": 1000,
"usd_value": 11.25,
"tx_hash": "…",
"send_error": null,
"client_order_id": "my-sale-1",
"address": "CLIENT_WALLET"
}Need a key?
Message shop support and ask for a reseller key. Keep it secret — it can create paid deliveries on your behalf.
