Zepto
Zepto is a Gold Coast, Australia based account-to-account (A2A) payments company that gives merchants and platforms programmable, real-time access to Australia's core money-movement rails. Its unified REST API moves money over the New Payments Platform (NPP) for instant account-to-account payments, PayTo for mandated real-time debits, PayID addressing, BECS Direct Entry (direct debit and direct credit), and stored-value float accounts, with real-time messaging, settlement and reconciliation. Zepto is the first non-authorised-deposit-taking institution (non-ADI) approved to connect directly to the NPP as a "Connected Institution" for PayTo, positioning it as an infrastructure-grade money-movement provider rather than a card acquirer. Its API posture is genuinely developer-first and API-native: a public ReadMe developer portal, a full sandbox, idempotent asynchronous payment flows, webhook notifications, and seven downloadable OpenAPI specifications covering the core payments API, PayTo, Confirmation of Payee (Validate), disputes, clients, merchant reports and notifications.
Zepto publishes 7 APIs on the APIs.io network, including PayTo API, Validate API (Confirmation of Payee), and 5 more. Tagged areas include Payments, Australia, Real-Time Payments, Account-to-Account, and New Payments Platform.
The Zepto catalog on APIs.io includes 1 event-driven AsyncAPI specification.
Zepto’s developer surface includes authentication, documentation, API reference, getting-started guide, changelog, engineering blog, sandbox, and 32 more developer resources.
Kin Score
APIs 7
Individual APIs this provider publishes, each with its own machine-readable definition.
Zepto API
Zepto's core account-to-account payments API — move money over the New Payments Platform (NPP), BECS Direct Entry and PayID with payments, payouts, payment requests, transfers, ...
Zepto PayTo API
Programmatic PayTo mandate management and real-time collection — create, amend, suspend, reactivate and cancel PayTo agreements, then collect authorised real-time payments and i...
Zepto Validate API (Confirmation of Payee)
Confirmation of Payee (CoP) account validation — verify that a payee's account name matches the account details in real time before initiating a payment, reducing misdirected pa...
Zepto Investigations API
Disputes and investigations (Beta) — raise and manage payment disputes, respond to action requests (accept, reject, upload evidence) and simulate incoming investigation messages...
Zepto Clients API
Client management (Alpha) — create and manage sub-clients and their Merchant Category Codes (MCC) for platform and marketplace models operating on top of Zepto's rails.
Zepto Merchant Reports API
Merchant reporting — download PayTo settlement reports by report date for reconciliation of collected and settled funds.
Zepto Notifications API (Webhooks)
Webhook event notifications — subscribe to asynchronous payment and account events (for example float_accounts.unmatched_credit.received) to drive real-time reconciliation and p...
Scroll for all 7
MCP Servers 1
Model Context Protocol servers that expose these APIs to AI agents.
zepto-payments-mcp.yml
MCP SERVEREvent Specifications 1
AsyncAPI definitions for this provider's event-driven and streaming APIs.
Security Posture 4
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Zepto Payments Trust Center
PCI DSS Level 1 (v4.0), ISO/IEC 27001, ASAE 3150 (independently certified by RSM Australia), CIS Benchmark Level 2, ISO 9362 (registered SWIFT BIC SPPYAU22)
SECURITYScopes 1
OAuth scopes governing access to this provider's APIs.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 4
Portal, sign-up, and the first successful call
Documentation 2
Reference material describing how the API behaves
Agent Surfaces 5
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 7
Pagination, idempotency, versioning, errors, and events
Scroll for all 7
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 8
Authentication, authorization, and security posture
Scroll for all 8
Operate 4
Status, limits, changes, and where to get help
Commercial 2
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
Other 1
Properties that don't map to a standard resource type