# Zepto

**Canonical:** https://apis.io/providers/zepto-payments/  
**Website:** https://zepto.com.au/  
**APIs profiled:** 7

Zepto is a Gold Coast, Australia based account-to-account (A2A) payments company that gives merchants and platforms programmable, real-time access to Australia's core money-movement rails. Its unified REST API moves money over the New Payments Platform (NPP) for instant account-to-account payments, PayTo for mandated real-time debits, PayID addressing, BECS Direct Entry (direct debit and direct credit), and stored-value float accounts, with real-time messaging, settlement and reconciliation. Zepto is the first non-authorised-deposit-taking institution (non-ADI) approved to connect directly to the NPP as a "Connected Institution" for PayTo, positioning it as an infrastructure-grade money-movement provider rather than a card acquirer. Its API posture is genuinely developer-first and API-native: a public ReadMe developer portal, a full sandbox, idempotent asynchronous payment flows, webhook notifications, and seven downloadable OpenAPI specifications covering the core payments API, PayTo, Confirmation of Payee (Validate), disputes, clients, merchant reports and notifications.

## Kin Score — 59.3 / 100 (strong)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 59.3).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 62.3 |
| Governance | 20.8 |
| Operational Transparency | 55.3 |
| Developer Ergonomics | 66.8 |
| Commercial Clarity | 50.0 |

Regulatory layer — **Banking & Open Finance**: 67.1 (matched via tags).

## Agent readiness — 61.0 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | verified |
| Error Semantics | verified |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (7)

- **Zepto API** — Zepto's core account-to-account payments API — move money over the New Payments Platform (NPP), BECS Direct Entry and PayID with payments, payouts, payment requests, transfers, ...
- **Zepto PayTo API** — Programmatic PayTo mandate management and real-time collection — create, amend, suspend, reactivate and cancel PayTo agreements, then collect authorised real-time payments and i...
- **Zepto Validate API (Confirmation of Payee)** — Confirmation of Payee (CoP) account validation — verify that a payee's account name matches the account details in real time before initiating a payment, reducing misdirected pa...
- **Zepto Investigations API** — Disputes and investigations (Beta) — raise and manage payment disputes, respond to action requests (accept, reject, upload evidence) and simulate incoming investigation messages...
- **Zepto Clients API** — Client management (Alpha) — create and manage sub-clients and their Merchant Category Codes (MCC) for platform and marketplace models operating on top of Zepto's rails.
- **Zepto Merchant Reports API** — Merchant reporting — download PayTo settlement reports by report date for reconciliation of collected and settled funds.
- **Zepto Notifications API (Webhooks)** — Webhook event notifications — subscribe to asynchronous payment and account events (for example float_accounts.unmatched_credit.received) to drive real-time reconciliation and p...

## MCP servers (1)

- **zepto-payments-mcp.yml**

## Agentic access (1)

- **Zepto Payments Agentic Access** — 72 operations · 37 acting · 1 human-in-the-loop

## Security (4)

- **Zepto Payments Authentication** — http/oauth2 · 2 schemes
- **Zepto Payments Domain Security** — TLSv1.3 · HSTS · DMARC
- **Zepto Payments Vulnerability Disclosure** — security.txt · contact published
- **Zepto Payments Trust Center** — PCI DSS Level 1 (v4.0), ISO/IEC 27001, ASAE 3150 (independently certified by RSM Australia), CIS Benchmark Level 2, ISO 9362 (registered SWIFT BIC SPPYAU22)

## Tags

Payments, Australia, Real-Time Payments, Account-to-Account, New Payments Platform, PayTo, PayID, Direct Entry, Open Banking, Money Movement

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/zepto-payments/). Scores are computed from the provider's own public artifacts under a published rubric.
