MercanPay Blog

Crypto Balance Withdrawal Process: Panel and API Guide

The MercanPay crypto balance withdrawal process: verification codes, saved addresses, payout statuses, fees and limits, webhook events and API payouts.

Published: October 2, 20265 min readTürkçe oku
Crypto Balance Withdrawal Process: Panel and API Guide

The crypto balance withdrawal process is the last step: moving the USDT and TRX you collected into your own wallet. On MercanPay, payments are credited to your balance after 20 block confirmations, and you can withdraw that balance to a TRON address whenever you like. This guide covers how a withdrawal starts in the panel, the stages it goes through, fees and limits, and automated payouts through the API.

Before you start: an Authenticator is required

To withdraw, your account needs an authenticator app (TOTP) such as Google Authenticator. You set it up under Settings → Security in about a minute; until then, the withdrawal screen sends you there first.

The reason is simple. A withdrawal is the one action an attacker wants to take on your account, so this is where the strictest checks sit. The full set of layers is in Crypto merchant account security.

Step 1: Save your withdrawal address

Under Saved addresses on the Balance page, add the TRON addresses you withdraw to, with a label such as "Main wallet" or "Exchange account".

  • Your first address is added without verification codes.
  • Later addresses need an email code and an Authenticator code.

Saved addresses are faster and safer than pasting a long address each time. The copy-paste risk is explained in Address poisoning attacks, and address format in TRC20 address format and validation.

The address must be on TRON (TRC20). When withdrawing to an exchange, use its TRON / TRC20 deposit address.

Step 2: Start the withdrawal

On the Balance page:

  1. pick the coin (USDT or TRX),
  2. enter the amount,
  3. choose a saved address or paste one,
  4. check the network fee and the total that will leave your balance.

Verification codes

Panel withdrawals ask for two codes:

  • An email code. The email states the amount, coin and destination address, so compare them before you enter the code.
  • An Authenticator code, the six digits from your phone app.

The one exception is trusted addresses you have deliberately set to code-free withdrawals. An address can be made trusted with your password, an email code and an Authenticator code once it is 7 days old and has received 3 completed withdrawals, or earlier if your early-unlock request is approved. Withdrawals to these addresses need no codes, and API withdrawals can only go to them.

Step 3: Follow the status

Once confirmed, the withdrawal is queued and moves through these statuses:

Status Meaning
queued Accepted and waiting to be sent
processing Being broadcast to the chain
completed Done on-chain; the TxID is shown
failed Sending failed; the amount went back to your balance
rejected Rejected; the amount went back to your balance

Withdrawals are usually sent within 1–10 minutes. A completed withdrawal shows its transaction ID (TxID), which you can check on a TRON block explorer.

A failed or rejected withdrawal doesn't lose money. The amount returns to your balance and shows as a withdrawal refund in the balance ledger.

Fees and limits

Item Value
Withdrawal fee $1–3 (per coin, shown on the withdrawal screen)
Minimum withdrawal $10 worth
Supported coins USDT and TRX, TRON (TRC20) only

The fee is deducted from your balance and shown upfront. Withdrawing in larger batches at intervals, rather than many small amounts, keeps the fee share low. For how costs arise on TRON, see TRON energy and bandwidth explained.

A quick pre-withdrawal checklist

A few seconds of checking before each withdrawal prevents mistakes that can't be undone:

  • Right network? The destination must be on TRON (TRC20). For an exchange, double-check the deposit network there.
  • Right coin? Make sure you're not sending TRX to a USDT deposit page or the other way round. The same address can hold both coins, but exchanges often have a separate deposit page per coin.
  • Exact address? Compare the destination in the email from start to finish, not just the first and last characters.
  • New address? Before sending a large amount to an address for the first time, send a test withdrawal of the minimum amount.

The 24-hour security lock

For 24 hours after a password reset or after turning off two-factor authentication, withdrawals are blocked. That stops someone who takes over an account from draining it straight away. If the change was yours, just wait it out. During the lock the API returns withdrawals_locked.

Withdrawal notifications

You hear about every outcome through several channels:

  • Panel notifications, in the Withdrawals category.
  • Email, if withdrawal emails are on (completed, failed, rejected). See Merchant notifications and activity log.
  • Webhooks: withdrawal.completed, withdrawal.failed and withdrawal.rejected. The data.withdrawal object carries id, status, token, amount, fee, to_address and txid. See Crypto payment webhook events.

Automated payouts with the API

Systems that pay out regularly, such as a weekly sweep to your main wallet, can use the API:

  1. Create a separate API key with the withdrawals scope, and don't add that scope to your store's invoices key.
  2. Make the destination a trusted (code-free) address in the panel. API withdrawals to other addresses fail with address_not_trusted.
  3. Send a unique idempotency_key with every withdrawal.
import os
from mercanpay import MercanPay, MercanPayError

zp = MercanPay("https://mercanpay.com", os.environ["MERCANPAY_PAYOUT_KEY"])

try:
    # retrying with the same key never creates a second withdrawal
    wd = zp.create_withdrawal(
        token="USDT",
        amount="500",
        to_address="T...",
        idempotency_key="weekly-sweep-2026-50",
    )
    print(wd["status"])                         # queued
    print(zp.get_withdrawal(wd["id"])["status"])
except MercanPayError as e:
    # e.g. address_not_trusted, withdrawals_locked, validation_error
    print(e.code, e.message)

In PHP the call is $zp->createWithdrawal('USDT', '500', 'T...', 'weekly-sweep-2026-50').

Why the idempotency key? After a network error you can't tell whether the request arrived. Retrying with the same key never sends the withdrawal twice. Keys that include a date or period, like weekly-sweep-2026-50, work well.

FAQ

My withdrawal is still "queued". Is that normal?

Withdrawals usually go out within 1–10 minutes. If one waits longer, open a support ticket from the panel with the withdrawal ID; see Merchant support tickets.

Can I use a withdrawal to refund a customer?

Yes. A crypto refund is a withdrawal from your balance to the address the customer gives you. See How to refund crypto payments.

Can I withdraw in fiat?

No. MercanPay doesn't pay out in fiat; withdrawals are USDT or TRX on TRON. For what comes next, see Converting USDT to Turkish lira.

Can a withdrawal to the wrong address be reversed?

No. A completed on-chain transfer is final, so use saved addresses and check the destination in the email before entering the code.

Get started with MercanPay

Accept USDT and TRX with a secure payout flow: apply as a merchant and see the documentation for API withdrawals.

#Withdrawals#Balance#Security#API

Related posts

Start accepting crypto payments in minutes

Accept USDT and TRX (TRC20). Fees from 0.4%, a hosted payment page, API and webhooks.