Knowledge Base Overview
Cashela API – Knowledge Base
The Knowledge Base is designed to help integrators, developers, and business teams understand the foundational concepts, compliance requirements, and operational best practices when working with the Cashela API.
It consolidates technical definitions, security guidelines, and usage workflows to ensure secure, compliant, and efficient integrations.
Core Concepts
API Authentication & Credentials
- Business Key and Business Secret are generated in the Cashela Business Dashboard.
- All API requests require Basic Authentication using these credentials.
- Enable IP whitelisting to restrict access.
Environments
- Sandbox for development and testing.
- Production for live transactions.
- Different Base URLs for each environment.
Financial Instruments Overview
Cashela enables global deposits through a diverse array of financial instruments. Each channel has unique operational characteristics and regional advantages, ensuring your business can support the most effective payment options per market.
Bank Transfers
These are traditional deposit channels where funds are transferred directly from a customer’s bank account. Cashela supports:
- ACH (Automated Clearing House) in the United States for low-cost, domestic transfers.
- SEPA (Single Euro Payments Area) for euro-denominated payments within Europe.
- SWIFT for international wire transfers across banks worldwide.
These methods are commonly used in B2B settings or for high-value transactions due to their reliability and auditability.
Card Payments
Cashela supports major card schemes including Visa, Mastercard, and American Express. Card payments are widely accepted and ideal for e-commerce, subscriptions, and instant deposits.
Digital Wallets
Digital wallets enable users to make payments using mobile apps or regionally popular payment rails. Cashela supports:
- Pix (Brazil)
- M-Pesa (East Africa)
- Tigo Money, Nequi (LATAM)
These instruments are especially valuable for reaching underbanked populations and mobile-first economies.
Vouchers
Vouchers act as prepaid codes that users can purchase from retail outlets or online, and redeem digitally. Cashela integrates with:
- Ualá, Western Union, Walmart, 7-Eleven
Cash Deposits
In countries where digital adoption is lower, Cashela supports physical cash deposit systems through agents or retail locations, such as:
- Boleto Rápido, Oxxo (Mexico)
- Bancolombia (Colombia)
Cashela dynamically exposes the appropriate methods per country and currency context during integration.
Compliance & Security
KYC/KYB Processes
Cashela enforces strict Know Your Customer (KYC) and Know Your Business (KYB) procedures before enabling production transactions. This ensures compliance with international anti-money laundering (AML) regulations and local licensing requirements.
KYC – For Individual Customers:
- Full name, date of birth, and nationality.
- Valid government-issued photo ID (passport, national ID, driver’s license).
- Proof of address (utility bill, bank statement).
- In some jurisdictions, selfie verification or biometric validation.
KYB – For Businesses:
- Certificate of incorporation or business registration.
- Tax Identification Number (TIN) or equivalent.
- Proof of address (lease agreement, utility bill).
- Identification and verification of company directors and ultimate beneficial owners (UBOs).
- Bank account verification for settlement purposes.
Cashela’s compliance team reviews and approves all KYC/KYB submissions before granting production API credentials.
Transaction Monitoring
- Real-Time Screening: Every transaction is screened against sanctions lists, politically exposed persons (PEP) databases, and high-risk jurisdictions.
- AML Pattern Detection: Automated systems identify unusual patterns, such as rapid high-value deposits or multiple small transactions indicative of structuring.
- Manual Review: Transactions flagged by the system undergo manual investigation by the compliance team.
- Reporting Obligations: Suspicious transactions may be reported to relevant financial intelligence units (FIUs) as required by law.
Data Protection
- PCI DSS Level 1 Compliance: Cashela adheres to the highest industry standards for payment card data security.
- Encryption in Transit and at Rest: All communication occurs over HTTPS with TLS 1.2+ and sensitive data is encrypted at rest using AES-256.
- No Plain Text Storage: Credentials, cardholder data, and sensitive identifiers are never stored in plain text.
- Data Minimization: Only essential personal data is collected, processed, and stored.
- GDPR & Data Privacy Compliance: For applicable regions, Cashela complies with GDPR and similar data protection laws.
Integration Best Practices
Error Handling & Retries
- Implement retry logic for transient errors (HTTP 5xx).
- Validate all request data locally before sending to API.
Webhook Security & Idempotency
- Verify source IP or authentication headers.
- Ensure your webhook processing is idempotent to handle retries safely.
Global API Guidelines
- Standard Error Model
- Idempotency Guidelines
- Webhook Signing & Security
- FX Behavior & Rate Locking
- Settlement Times & Processing Flows
- Field Validation Rules
- Rate Locking Rules (Quotation)
Terminology & Conventions
- Country codes: ISO-3 (e.g., MEX, USA, BRA)
- Currency codes: ISO-4217 (e.g., USD, MXN, BRL)
- Field names: snake_case (e.g., first_name, last_name, external_identifier)
- GET endpoints use query parameters only (no request body)
Developer Resources
- API reference documentation.
- Example requests and responses for all endpoints.
- Testing guidelines for QA validation.