Architecture

How QashX Pay stays provider-agnostic — capabilities in, providers hidden.

Clients request a capability (Card, SEPA, SWIFT, USDC, EURe, …). The Routing Engine picks a provider adapter based on cost, availability, and compliance. The frontend never names Stripe, Bridge, Compose, or Monerium.

Layered view

Client

Your app, our SDKs, or the QashX Pay checkout. Talks to the public API only.

Public API

api-v1-* edge functions. Authenticates keys, enforces scopes, rate-limits, and validates payloads.

Orchestrator

PaymentOrchestrator writes the unified qashx_payments row and posts to the ledger.

Capability Registry

Maps method_kind + currency + region to eligible capabilities.

Routing Engine

Selects an adapter by policy — cost, latency, provider health, compliance rules.

Provider Adapters

Isolated modules per provider. Never share state. Called via a common ProviderAdapter interface.

Providers

Stripe, Bridge, Compose, Monerium, on-chain settlement — the outside world.

Ledger

qashx_ledger_entries — double-entry, atomic via SECURITY DEFINER RPCs.

Reconciliation

Hourly sweeps match provider records to ledger. Drift raises alerts to Ops.

Payment flow

Client Public API Orchestrator Routing Engine Adapter Provider | | | | | | |-- POST /payments -->| | | | | | |-- authn + scope -->| | | | | | |-- resolve cap ----->| | | | | | |-- pick adapter ---->| | | | | | |-- create intent --->| | | | | |<-- provider_ref ----| | | |<----- adapter result ---------------------| | | | |-- ledger post ----->| | | |<--- 201 payment ----|<-------------------| | | | | | | | |<- webhook async ----| |<-- webhook to you --|-- signed HMAC -----|-- state transition -| | |

Routing decision inputs

InputSourceEffect
Capability matchCapability RegistryFilters to adapters that can serve the request.
Provider healthOps metricsExcludes adapters currently degraded.
Cost tierFee configPrefers lower-fee provider when tie-broken.
Compliance rulesqashx_pay_risk_rulesBlocks sanctioned corridors, region mismatches.
Settlement preferenceMerchant configPins EURC/USDC to Base per stablecoin guard.
Explicit overrideAdmin toggleForce-routes a corridor during incident response.

Provider isolation

This is why your integration survives provider changes. You wrote against a capability; we route it.