Built for the way
modern teams spend
Every feature is designed to reduce friction and increase control.
Virtual Cards
Instant Card Issuance
Issue Visa virtual cards in seconds via our card issuer integration. Full three-element delivery (PAN, CVV, expiry).
Card Face with Masking
Card numbers are masked by default. Reveal them securely with Step-up verification. Auto-hides after 30 seconds.
Balance Management
Each card has its own balance. Top-up anytime. The card balance is separate from the workspace wallet.
Freeze & Unfreeze
Temporarily freeze a card with a single click. Unfreeze anytime. No fees, no delays.
Card Close
Close a card permanently. Remaining balance is automatically returned to the workspace wallet.
Cardholder Name
Cards are issued in the cardholder's name — perfect for staff expense management.
Team & Approval
Staff Seats
Invite team members to your workspace. Each staff member gets their own login and can hold multiple cards (requires STAFF_SEATS subscription).
Approval Workflows
Staff submit card issue / top-up / close requests as tickets. Owners approve or reject with one click.
Role-based Access
Delegates can be granted owner-level access with fine-grained RBAC permissions.
Multi-workspace
Manage up to 5 workspaces from one account. Switch instantly from the dashboard.
Staff TOTP
Staff members can optionally enable TOTP two-factor authentication for their accounts.
Ticket Comments
Owners and staff can exchange messages on tickets — request more info, or explain rejections.
Wallet & Funds
USDT Deposit (TRC20)
Fund your workspace wallet with USDT via TRC20. Funds appear in your USD balance after blockchain confirmation.
Real-time Ledger
Every credit and debit is recorded in the ledger with reason codes, amounts, and timestamps.
Withdrawal Request
Request USDT withdrawals via a managed approval flow. Platform admins process withdrawals within 1–3 business days.
Fee Transparency
All fees shown upfront before any action: $3 card issuance, 3% top-up, $2 + 1% deposit. No surprises.
Hold Balance
Funds held for pending operations are shown separately, so you always know your true available balance.
Multi-currency Display
Card transactions in non-USD currencies are shown with original amount and converted USD equivalent.
Security & Compliance
PCI DSS Compliant
Card secrets stored with Envelope Encryption (KEK + DEK). Never exposed in logs, API responses, or databases in plaintext.
Step-up Authentication
Sensitive operations (withdrawal, card reveal, API key) require re-verification via password or TOTP 2FA.
Bearer Token Auth
Stateless Bearer token authentication — no session cookies, no CSRF. Compatible with SPA and mobile apps.
TOTP 2FA
All users can enable TOTP two-factor authentication. Platform administrators are required to use it.
Immutable Audit Log
Every financial operation is permanently logged with actor identity, timestamp, and full payload.
Admin IP Allowlist
The admin portal access is restricted to configurable IP addresses. Zero risk of admin panel exposure.
Developer Tools
REST API
Full REST API access to all workspace resources. Issue cards, check balances, approve tickets — all programmatically.
Webhook Events
Real-time event delivery for transactions, card issuance, deposits, and ticket status changes to your endpoint.
Webhook Retry
Failed webhook deliveries are automatically retried. Manually re-trigger individual deliveries from the dashboard.
API Token Management
Create named API tokens with optional expiry. Revoke tokens instantly from the developer settings.
Encrypted Card Secrets
Upload your RSA-4096 public key. Card secrets are delivered as JWE-encrypted payloads — only you can decrypt.
Webhook Signing
Every webhook payload is signed with a unique HMAC secret. Rotate the secret anytime from the dashboard.