Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To add exchange deposits to an app with Turnkey embedded wallets, resolve the user’s approved receiving account on your server, create a Canopy payment intent for that destination, save the intent and its deposit inbox against that user, and confirm settlement from a verified server-side webhook. A direct exchange withdrawal can also work without Canopy if the exchange supports the exact token and network for the intended receiving address. Creating an intent—or seeing a browser checkout event—does not prove that funds have settled.

What this integration does—and what your app must provide

Canopy’s payment-intent flow gives an end user a deposit inbox and reports settlement for supported, provisioned routes. Your app connects that flow to the right Turnkey account. It is an integration pattern, not a starter application: your team supplies authentication, account ownership checks, persistent storage, API routes, webhook processing, and any wallet-balance refresh or ledger logic.

  • Your server identifies the signed-in user, resolves their selected Turnkey destination, creates or resumes a deposit record, and calls Canopy with server-held credentials.
  • The browser requests a deposit for the signed-in user, displays the selected receiving account and network, and opens checkout using the saved intent.
  • Your webhook handler and worker verify and durably record settlement notifications, then reconcile each business effect once.

Canopy’s API documentation describes the core pattern this way: “Create a payment intent for each end user who is about to move funds, then hand that user a deposit address unique to them.” The Canopy inbox is a deposit address for the payment flow; it is not the same thing as the user’s Turnkey receiving address.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Confirm the route and account model before accepting funds

Check the complete route

Before exposing a deposit option, confirm with Canopy that the route is supported and provisioned for your merchant. Check the source asset and exchange withdrawal network, destination chain and token, minimum amount, and payout configuration together. The tutorial’s Base example uses chain reference 8453; that example does not establish that a Base route is enabled for your merchant.

#1 Best Overall
Sale
Ledger Nano X - Classic Crypto Wallet with Bluetooth
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
  • Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
  • Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
  • Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.

Per-intent payout destinations require both the merchant’s per-intent destination setting to be enabled and Canopy to provision the route in Dynamic payout mode. Intent creation succeeding is not evidence that the user’s funds have arrived.

Choose the address whose balance the app means to show

A Turnkey wallet can derive multiple accounts. A signer address and a separate smart-account address are not interchangeable: funding the signer does not automatically fund the smart account. If the app displays a smart account’s balance, resolve that actual smart-account destination for the deposit rather than assuming that sending to its signer will move funds there.

Decide which account a user selected for deposits and maintain a verified mapping to it. Store its Turnkey organization ID, wallet ID, and wallet-account ID, along with the normalized destination address and the application user ID. If a user changes accounts, treat that as an explicit destination change; do not silently switch to another account returned by a list.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
TANGEM Crypto Wallet Pack of 2 – Trusted Cold Storage Hardware Wallet
  • Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
  • Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
  • Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
  • Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
  • Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets

Resolve the receiving account on the server

  1. Authenticate the request. Verify the application session or provider token on the backend. Do not let a browser-provided user ID establish ownership.
  2. Load the user’s approved destination. Use an authenticated Turnkey account lookup or a previously verified application mapping. Confirm that the signed-in user is authorized to fund that account.
  3. Reject ambiguity. If the user has more than one possible destination and no explicit selection, require a choice. Do not use the first wallet or account in a response as a shortcut.
  4. Bind ownership durably. Enforce unique ownership for individual user destinations where appropriate, and retain the organization, wallet, wallet-account, and user identifiers with the selected address.

The browser should request a deposit for the authenticated user, not nominate an arbitrary payout address. This prevents a modified client request from redirecting the intent to an address the user has not been approved to fund.

Create the intent and persist its owner relationship

Your backend calls Canopy’s /api/v1/intents endpoint with a server-only bearer secret, a Canopy-Version header, and JSON. The destination configuration identifies the payout wallet, namespace, chain reference, and token address. Canopy documents the destination as write-once after the intent exists, so resolve and validate it before creating the intent.

  1. Reserve or resume a local deposit record for the authenticated user and selected Turnkey account.
  2. Serialize creation for that destination. Canopy allows at most one active intent for a merchant account, payout namespace, chain, wallet, and token. Concurrent requests for matching terms should not race through your application as independent creates.
  3. Create or retrieve the matching intent. A repeated create with matching destination terms returns the existing intent with created: false and a fresh widget token. A retry rotates the prior widget token. A repeated request without destination fields always creates a new intent.
  4. Save before responding. Persist the Canopy intent ID, inbox address, immutable destination, Turnkey account identifiers, and application user ID before returning the intent ID or widget data to the browser.
  5. Retain uncertain reservations. If a request times out and the outcome is unknown, preserve the local record and reconcile it rather than assuming that Canopy did not create the intent.

Canopy does not provide request idempotency through merchantReference; it is a correlation value, not a deduplication key. Your application’s persistence and serialization are therefore important both for retries and for associating a user with the correct intent.

Rank #3
Trezor Safe 3 Crypto Hardware Wallet with Secure Element
  • Unparalleled Security: Protect your assets with EAL 6+ Secure Element, offering robust defense and complete transparency
  • Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
  • Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
  • Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
  • Enhanced Backup Solution: Multi-share Backup eliminates single points of failure for secure cold wallet recovery

Present checkout and exchange instructions clearly

Show the receiving Turnkey account and intended destination network near the checkout flow so the user can verify where the app expects the funds to end up. In Canopy checkout, the user selects an enabled source asset and network and receives the deposit address to use in the exchange’s withdrawal flow. Tell the user to select the displayed network exactly. An EVM-compatible address format alone does not tell the user which EVM network to choose.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not label the Canopy inbox as the user’s permanent or universal wallet address. Keep it distinct in storage and on screen from the Turnkey receiving address; the inbox belongs to the deposit flow, while the Turnkey address is the intended payout destination.

Inline checkout requirements

  • Register the exact HTTPS origin for the publishable key: scheme, host, and port, without a path, query, or fragment.
  • The embed guide uses the SDK’s mount() function for inline checkout and supports surface: "auto". That setting falls back to a popup button if the frame cannot complete its handshake.
  • Destroy the returned checkout handle when the component unmounts.

Verify settlement and reconcile effects once

The browser’s Canopy checkout paid event is an advisory UI signal: the embed guide says it means the payer’s transfer was seen on-chain. Do not credit an internal balance or mark the deposit complete from that event. Confirm fulfillment with a server-side status check or a verified webhook; the flow here uses the signed settlement webhook.

Rank #4
Trezor Safe 5 Crypto Hardware Wallet with Color Touchscreen
  • UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
  • EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
  • ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
  • SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
  • EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app

Verify the webhook before trusting its payload

  1. Read and retain the raw request body so signature verification uses the original bytes.
  2. Verify the signature and timestamp before acting on any payload fields. Canopy documents the webhook-id, webhook-timestamp, and webhook-signature headers; its standardwebhooks verifier checks the signature and timestamp tolerance.
  3. Persist a verified delivery durably before acknowledging it. Deduplicate delivery IDs, and separately deduplicate the business operation so webhook retries cannot produce duplicate effects.
  4. Queue reconciliation and act only when the verified payload’s state is settled.

Canopy’s documented webhook body is flat and contains a state field; it does not require an outer event.type wrapper. The documentation says payment.settled is currently emitted with state: "settled". It documents payment.failed, but says that event is not currently emitted. Branch on the verified state rather than assuming an event-type envelope or treating every delivery as a successful deposit.

Keep payment accounting separate from wallet balances

Keep amount fields such as netUnits and feeUnits as integer strings until the relevant route’s units and decimals have been confirmed. A wallet balance refresh and an internal ledger credit are different operations. If your app only displays the assets held in the user’s wallet, record the funding history and refresh that wallet view; do not invent a second spendable balance that duplicates the on-chain funds.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose direct withdrawal or a routed deposit flow

Approach What it does When it fits What to confirm
Direct exchange withdrawal Sends from the exchange to the selected receiving address without a Canopy intent. The exchange supports the exact token and destination network the application requires. Exchange network and token match the intended receiving account; a direct withdrawal does not use Canopy’s intent or checkout flow.
Canopy payment intent Provides a deposit inbox and settlement reporting for routes Canopy supports and has provisioned. The app needs Canopy’s deposit instructions and settlement flow for an available route. Source asset/network, destination chain/token, minimum, per-intent destination configuration, and route availability.
LI.FI Smart Deposit Addresses LI.FI describes unique deposit addresses that can orchestrate token swaps, cross-chain transfers, vault deposits, and composed actions. The application needs broader routing or a composed action beyond a simple deposit. Supported source combinations, destination, minimums, availability, payout controls, and settlement reporting for the intended use case.

These options are not interchangeable on every route, and the available information does not establish a universally best provider or partnership terms. Compare the exact asset/network combinations and destination controls for the app’s use case rather than choosing from a provider name alone.

Best Value
Ledger Nano S Plus - Classic Crypto Wallet
  • All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
  • Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
  • Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
  • Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
  • Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.

What the tutorial’s checks do—and do not—establish

The Canopy tutorial reports that its example passed a production build, fixture tests, a browser exercise, and a restart-persistence check using specified dependency versions. It also states that these checks used synthetic accounts and Canopy responses; real Turnkey account lookup, hosted Canopy checkout, and a funded settlement were not verified. Those checks are useful implementation signals, not evidence of a completed real-world deposit.

Keep Canopy Pay’s exchange-deposit flow distinct from the separately named Canopy investor-allocation funding product. The latter concerns funding an investment allocation and is not this payment-intent integration.

Quick Recap

SaleBestseller No. 1
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Ledger Nano X - Classic Crypto Wallet with Bluetooth
Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
$79.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.