Esta guía te lleva de cero a un cobro real en USDT TRC20 en sandbox, después flipeás una variable y estás en producción. Ningún paso lleva más de 60 segundos.
Creá tu cuenta gratis en getcwallet.app, andá al Dashboard de comercios y copiá la API key sandbox (empieza con cwt_test_) desde la pestaña Sandbox.
Cada cuenta recibe automáticamente dos keys: una sandbox (no mueve plata real) y una live (USDT TRC20 mainnet). Empezás siempre por sandbox.
Desde tu backend, hacé un POST con tu API key como Bearer. Recibís el intent.id + checkout_uri.
# cURL
curl -X POST https://getcwallet.app/api/v1/create-payment-intent \
-H "Authorization: Bearer cwt_test_XXXXXXXX" \
-H "Content-Type: application/json" \
-d '{"amount_usdt": 25.50}'
# Response:
# {
# "success": true,
# "environment": "sandbox",
# "livemode": false,
# "intent": {
# "id": "11111111-2222-3333-4444-555555555555",
# "amount_usdt": 25.50,
# "status": "pending",
# "expires_at": "2026-05-20T15:30:00Z",
# "checkout_uri": "cwallet:pay?intent=11111111-..."
# }
# }La opción más rápida es nuestro widget — un script CDN que abre un modal con QR + status polling automático. Tu backend pasa el intent.id, el widget se encarga del resto.
<!-- HTML -->
<button id="pay-btn">Pagar $25.50 USDT</button>
<script src="https://getcwallet.app/sdk/v1/checkout.js"></script>
<script>
const cwallet = new CWalletCheckout();
cwallet.renderButton({
elementId: 'pay-btn',
createIntent: async () => {
// Tu backend crea el intent (no expongas la API key en el browser)
const r = await fetch('/api/create-intent', { method: 'POST' });
return r.json(); // { intent_id, environment, amount_usdt }
},
onSuccess: (event) => location.href = '/thanks?id=' + event.intent_id,
onCancel: () => console.log('Usuario cerró el modal'),
onExpired: () => alert('Pago expirado'),
});
</script>CWallet hace POST a tu webhook con un header X-CWallet-Signature que es el HMAC-SHA256 del body usando tu webhook secret. Validá antes de marcar la orden como pagada.
// Node.js + Express
import crypto from 'node:crypto';
import { CWallet } from '@cwallet/node-sdk';
const cwallet = new CWallet({ apiKey: process.env.CWALLET_API_KEY });
app.post('/webhooks/cwallet', express.raw({ type: 'application/json' }), (req, res) => {
try {
const event = cwallet.webhooks.constructEvent(
req.body, // raw Buffer
req.headers['x-cwallet-signature'],
process.env.CWALLET_WEBHOOK_SECRET,
);
switch (event.event) {
case 'payment.success': markOrderPaid(event.intent_id, event.amount); break;
case 'payment.expired': cancelCart(event.intent_id); break;
case 'intent.created': logIntent(event); break;
case 'key.rotated': invalidateKeyCache(event.terminal_id); break;
case 'test.ping': console.log('Webhook OK'); break;
}
res.json({ received: true });
} catch (err) {
res.status(401).end(); // signature inválida → 401
}
});Cuando tu integración funciona end-to-end en sandbox, cambiás la API key de cwt_test_… a cwt_live_… en tu servidor y listo. Mismo código, ahora movés USDT TRC20 real. Cap diario configurable, retiros con aprobación admin para montos grandes, custodia cold storage multi-firma sin re-hipotecación.
# .env.production
CWALLET_API_KEY=cwt_live_XXXXXXXXX # ← solo esto cambia
CWALLET_WEBHOOK_SECRET=<live secret> # rotalo desde el dashboard
# Mismo código, ahora en mainnet
# Los webhooks llegan con X-CWallet-Livemode: trueSi los 5 pasos te quedaron claros, vas a querer explorar: