Integration Overview
PayTo Integration Overview
This document will guide you through the integration steps for Zepto PayTo solution.
Get paid in realtime with PayTo in 3 simple steps
A simple, modern payment experience from agreement creation through to payment collection.
Agreement
Create the PayTo agreement with payer details and payment terms.
Agreement
- Merchant instantiates agreement
- Payment terms are defined
- Payer details are included
Agreement Authorisation
The payer reviews and authorises the agreement in their banking experience.
Agreement Authorisation
- Authorised by the debtor
- Debtor can manage the agreement
Payment
Once authorised, payments can be pulled based on the agreed schedule or use case.
Payment
- Merchant pulls payments
- Supports adhoc, recurring or scheduled frequency
Integration Steps by Risk Classification
PayTo's real-time, irrevocable nature makes trust and security foundational to the ecosystem, for merchants, financial institutions, and customers alike. As part of Zepto's ongoing commitment to a safe and secure PayTo ecosystem, integration requirements vary based on the Merchant's risk classification.
Risk classification is determined during onboarding, in partnership with Zepto's Compliance team. Once classification is confirmed, the corresponding integration path below should be followed.
Low Risk Merchants
If you're classified as a low risk merchant, proceed with the standard integration steps outlined below (Agreement → Agreement Authorisation → Payment). No additional steps are required.
High Risk Merchants
Merchants flagged as higher risk are subject to additional safeguards on top of the standard integration steps. These exist to protect the integrity of the broader PayTo ecosystem: reducing fraud exposure, strengthening counterparty visibility, and ensuring every participant meets a consistent security bar.
- Counterparties endpoint: Integrating with the new Counterparties endpoint is required as part of the implementation prior to creating a PayTo Agreement. A counterparty record functions similarly to a Profile for an authenticated user, allowing Zepto to identify the individuals or entities involved in a transaction and maintain a trusted network for all participants.
- Compliance & Solutions review: Zepto's Compliance and Solutions team will work directly with the merchant to ensure the implementation meets all requirements for a secure integration.
See Counterparties guides for more information.
Not sure which category applies to you?
Reach out to your Zepto onboarding contact or the Compliance team to confirm your risk classification before starting integration.
High-level workflow

PayTo Agreements
Before funds can be collected from a customer, an authorised PayTo Agreement must be established. This is the consent model that sits between you and your end customer, allowing your business to collect funds from their nominated bank account (as long as the payment complies with the terms of the PayTo Agreement).
When a PayTo Agreement is created for your customer, they will receive a notification from their financial institution informing them of the pending Agreement awaiting their authorisation. Depending on the financial institution, and the banking channel used by the customer, that notification may be delivered via a number of channels including native app notification, email, text message - notification methods are entirely up to the receiving Financial Institution.
Once notified, the customer has 5 days to Authorise the Agreement (Accept or Decline). If they have not responded within this timeframe, the Agreement will automatically expire.
Once Accepted, the Agreement will become Active and can then be used for all subsequent PayTo activities.
Agreement Lifecycle

Agreement Authorisation
Wait for your customer to action the PayTo Agreement from within their banking portal/app:
Pre-authorised Agreement Actions
| Customer Actions | Result |
|---|---|
| Authorise | If they choose to Accept the Agreement, the state of the Agreement will move from: Created > Active |
| Decline | If they choose to Decline the Agreement, the state of the Agreement will move from: Created > Declined |
| Nothing | If the customer does nothing, then after 5 days the Agreement will become Expired and the state will move from: Created > Expired |
At any point in time, you may initiate a Cancellation:
| Merchant Action | Description |
|---|---|
| Pre-authorisation Cancel | In a scenario where a PayTo Agreement has been incorrectly issued and the customer has not yet actioned it, a Cancellation can be used to recall it. This will allow you to create a new Agreement with the correct information. Created > Cancelled |
| Post-authorisation Cancel | In the scenario where the Agreement has reached end-of-life, Cancellations should be used to ensure that a proliferation of active unused/unusable Agreements are not held Active within the NPP. Created > Cancelled |
Important
A PayTo Agreement can not be used to collect funds until it has been Accepted. It must be in an Active state in order to initiate Payments against it.
Post-authorised Agreement Actions
Once a PayTo Agreement has been Authorised by your customer, it will move into the Active state at which point the following actions are supported:
| Action | Description |
|---|---|
| Suspended/Reactivated | This action can be performed by:
|
| Cancelled | This action can be performed by:
|
| Amended | This action can be performed by:
|
PayTo Payment
Once an Active PayTo Agreement is in place between you and your customer you can start collecting funds as long as the collection request falls within the agreed terms of the Authorised Agreement.
Zepto will validate all PayTo Payments against the PayTo Agreement supplied and will reject any Payments that fall outside of the agreed terms.
Once a PayTo Payment has been validated and submitted onto the NPP, it is irrevocable and cannot be cancelled.
Payment Flow

Updated 19 days ago
