Learn

How Do I Add a Fiat-to-Crypto On-Ramp to My App via API?

A shop that doesn't take cards sends customers to the cash machine across the street, and some of them don't come back. An app without an on-ramp does the same thing. The user buys crypto somewhere else, and the wallet they fill there is the one they keep using.

You have three ways to keep that moment in your product. Send users to a provider's checkout page, build payments and compliance in-house, or connect with a provider by API. With an API, the provider still takes the payment and confirms who the user is, while your app shapes everything around it.

This guide explains who owns each part of the work, where launches tend to stall, and what to ask a provider before your team commits.

September 25, 2026

What does it mean to add a fiat-to-crypto on-ramp to an app?

An on-ramp lets someone turn regular money, like euros on a debit card, into crypto in a wallet. On the API route, your app owns the user relationship, and the provider takes care of payment and identity checks. The table below shows who does what.

Your app

The provider

Shows the price before the user commits

Charges the card or other payment method

Sets up the order, including the user's wallet

Verifies the user's identity

Follows each order through to completion

Delivers the crypto to the wallet

For example, with a provider like Mercuryo, you can plan the project around the widget, the checkout window where users pay. The company explains that with an API, the provider controls the core purchase flow. Within that setup, you choose how users reach it, whether through a redirect, an embed in your page or a mobile app, per its integration methods.

Why use an on-ramp API instead of building it in-house?

Building in-house means running each of these yourself.

  • Card acquiring, the service that accepts and settles card payments
  • Identity and anti-money laundering checks, with rules that differ by jurisdiction and change over time
  • Crypto delivery on every blockchain network you support

Hand them to a provider and most of that work moves to its side. Compliance moves only in part. Mercuryo's own guide notes that the compliance duties left with your company depend on where and how you operate. Have your legal team review them for each market before launch.

What does integrating an on-ramp API involve?

An API integration moves through four stages, and your team's role changes at each one.

1. Access and approval

Every provider sets up your test access and runs a business review on your company, a check known as KYB. With Mercuryo, an integration manager handles the access, and it arrives before that review is finished, so your engineers can start while the provider checks your company.

That review typically takes about a week, which makes it the first date to put in your launch plan. Ask any provider whether your team can start building before the review clears.

2. Sign-in

A second login in the middle of a purchase gives users one more reason to leave. Silent authentication lets your users skip the login step in the checkout window. The account stays on Mercuryo's side, and no user login details are shared with you. Ask your provider whether users have to log in again at the payment step.

3. The purchase

Before the payment step, your app can show the current exchange rate and fee in its own design. It can also pass along order details such as the user's wallet address, so users don't have to type them in.

Expect the link that opens the checkout to carry a security signature, so the provider can tell it came from you. With Mercuryo, that signature is mandatory whenever a purchase starts. When it's missing or wrong, the user sees an error and can't pay, so ask your engineers to confirm it works early in testing.

4. Order updates

Once a user pays, your app needs to know how the order ended. The recommended way to get that answer is callbacks, automatic notices sent to your system every time a transaction's status changes.

If your system is down when a notice arrives, delivery attempts continue for up to three days. A short outage on your side only delays the update.

How is KYC/AML handled within the integration?

KYC (know your customer) and AML (anti-money laundering) checks confirm who a user is before money moves. In the default setup, these checks run inside the checkout window, so your team has nothing extra to build.

When users go through KYC

Every crypto sale requires it. For purchases, it depends on the amount, the user's country and the payment method. Documents vary by market too. Verification typically pairs an ID with a selfie, and some countries ask for extra paperwork. Ask your provider which of your markets require a check, and whether it accepts verification you have already done.

KYC sharing

If your app already verifies users through Sumsub, an identity verification company, KYC sharing can pass along the result for users with an approved status. Users then don't have to repeat the process. Each shared check works only once per applicant, so treat it as a one-time transfer for customers you've already verified.

How do I test in sandbox and go live?

Testing and launch run on two tracks, with engineers checking the purchase flow while your business team finishes the paperwork.

Test in sandbox

A sandbox is a test environment that mirrors the live service without moving money. With Mercuryo, the purchase flow matches the live service, and test cards and test versions of the Bitcoin and Ethereum networks let your team try the full flow, including declined payments.

Where launches stall

The troubleshooting guide points to a few setup problems that can hold up testing or block purchases.

  • The test environment stays locked until your integration manager approves your team's network addresses.
  • If the checkout window is embedded in your site, it won't load unless the website address saved in your dashboard matches that site.
  • The buy button stays unavailable when the wallet address is wrong or the user hasn't accepted the terms and conditions.

Go live

The switch to the live service is mostly engineering work. The five-step launch checklist covers swapping test settings for live ones and ends with a small live transaction before full launch, so you see a purchase go through with live funds before users do.

On the business side, the partner onboarding process also includes a legal stage to finalize contracts. Start it alongside the build so it's done by launch day.

How does pricing and revenue share work?

Start with the customer side. Every provider sets its own buying fee, and it is the first number to look at. Mercuryo, for example, lists a buying fee of up to 3.95%. That fee affects what users pay at checkout, so factor it into product decisions early.

The other half is your agreement with the provider. Bring these commercial questions to the contract discussions in the legal stage of onboarding.

  • How does your expected transaction volume affect the commercial terms?
  • Which countries and payment methods can your users access today?
  • Who absorbs the cost of disputed or reversed card payments?

Why do developers choose Mercuryo's API?

With this route, the build doesn't wait on paperwork. Mercuryo gives you test access while it reviews your company, so your engineers can put the purchase together and try it out while the rest of the process moves.

After that, the work splits cleanly. The provider handles the core of the purchase, from payment and identity checks to crypto delivery, while your team keeps the screens around checkout and the relationship with each user. You decide where and when users see the offer to buy crypto.

To try the API with your app, the next step is to request sandbox access.

Frequently asked questions

  • Does the API replace the checkout window? The API works alongside it. Your app shows prices, handles sign-in, and tracks orders, while the payment itself happens in the widget.
  • Do users need a second login to buy? With silent authentication, users skip the extra login.
  • How long does KYB take? Timelines vary by provider. With Mercuryo, it takes about a week, and test access arrives before it finishes, so engineering can start right away.
  • Can I test without spending money? Any serious provider gives you a test environment. Mercuryo's uses test cards, and no money moves.
  • How does my app know a purchase completed? Your system receives a notice whenever a transaction's status changes, and delivery attempts continue for up to three days if it can't get through.
  • Can users sell crypto through the same integration? Yes. The API also covers selling, and every sale requires KYC.