Skip to main content
Malaysian e-money infrastructure

Embed a wallet in your product

Your brand, your screens, your user accounts. We hold the money, the ledger and the licence — which is why identifying the customer is our obligation rather than yours.

Sandbox api-wallet.dev.gohubpay.com.my/api/v1/walletProduction api-wallet.gohubpay.com.my/api/v1/wallet

One API, three credentials

There is one reference covering everything your integration can call. What differs between operations is whose authority the call carries — and every operation says which it takes, at the top of its own page.

Machine token34

Your backend, acting as your company

Register customers, open wallets, post transactions, read the ledger, create top-up links.

User token24

Your app, acting for one person

Everything under /me — top-ups, withdrawals, payout accounts, notifications. A machine token is rejected.

Either token13

Both, with different scope

Wallet and transaction reads, transfers. Each says on its own page what changes with the caller.

What is built, and what is not

We would rather you read this here than discover it in an error response. Anything partial says so on its own reference page, on the exact field that behaves differently.

LiveWallets, transactions, transfers, ledger and top-ups
LiveSubject registration and email contact verification
PartialKYC evidence capture — adjudication is ours, not yours
PartialAdjustments credit only; DEBIT returns 422
Not builtSMS verification — the API accepts it and returns 501
Not builtAutomated eKYC, and outbound webhooks to your endpoint