Skip to main content
Try Cobo WaaS Skill in your AI coding assistant (Claude Code, Cursor, etc.). Describe your needs in natural language to auto-generate production-ready SDK code and debug faster 🚀
After you have familiarized yourself with Custodial Wallets through the Cobo Portal quick start guide, this guide will help you seamlessly integrate Custodial Wallet (Asset Wallets) functionality into your application using the WaaS 2.0 API. Following this guide, you’ll learn how to:
  1. Create a wallet
  2. Generate a deposit address within the wallet
  3. Deposit tokens into the wallet and track the transaction status
  4. Withdraw tokens from the wallet
  5. Query wallet balances
  6. Automatically sweep funds to a designated address
This guide uses the development environment in all its code samples. It is recommended that you use the development environment to test your new features first before deploying them to the production environment.

Prerequisites

  • Follow the instructions in Send your first request to set up your account and send your first API request to the WaaS 2.0 service.
  • If you choose to use a WaaS SDK instead of manually writing the API requests, refer to the SDK guide corresponding to the programming language of your choice (Python, Java, Go, JavaScript) to integrate the SDK into your project.

1. Create a wallet

To create an Asset Wallet, call the Create wallet operation and specify the properties in the request body as follows:
  • wallet_type: Custodial.
  • wallet_subtype: Asset.
Upon successful completion of the request, the response will include the wallet ID, which is the unique identifier of the wallet you have just created. Store this wallet ID as you will need it for subsequent steps.

2. Generate deposit addresses

After setting up a wallet, you now need to generate deposit addresses within the wallet to receive tokens. To generate deposit addresses within the Asset Wallet you have just created, call the Create addresses in wallet operation and specify the parameters and properties as follows:
  • Path:
    • wallet_id: The ID of the wallet you have just created.
  • Request body:
    • chain_id: The ID of the blockchain.
    • count: Use this parameter to specify the number of addresses you want to create.
Upon successful completion of the request, the response will include the addresses you have just created. You can now proceed to deposit tokens into these addresses.

3. Process deposit

After depositing tokens to the addresses you have generated, you can track the status of your deposit using one of the following two options. Compared with using API to query the transaction status, webhooks can give you real-time notifications and are thus the recommended option.

Option 1: Use webhooks for real-time notifications

Webhook is an essential mechanism for the WaaS service to communicate with your application. After you register a webhook endpoint on Cobo Portal, the WaaS service sends push messages to the designated URL when an event occurs. To learn how to set up a webhook endpoint and register it on Cobo Portal, refer to Introduction to webhooks and callbacks. To track the status of your deposit, you can subscribe to the following webhook event types:
  • wallets.transaction.created
  • wallets.transaction.updated
  • wallets.transaction.succeeded
  • wallets.transaction.failed
To learn the trigger condition and data structure of each event type, refer to Webhook event types and data types.

Option 2: Get transaction status by API call

To query the status of a deposit transaction, call the List all transactions operation and set the query parameters as follows:
  • types: Deposit.
  • statuses: Confirming,Completed. If you are depositing from an external address, you will be able to query the transaction details when the transaction is waiting for the required number of confirmations or when it is successfully completed.
  • wallet_ids: The ID of the wallet you have created in the first step.

Deposit prerequisites

Before you deposit tokens, make sure the chain is activated for your organization and the token is listed and enabled for deposits. A token accepts deposits only when its can_deposit property is true. Deposits made to a token that is not enabled (can_deposit is false, meaning deposits are currently suspended) may not be detected or credited automatically, so confirm this property before you send funds. Check whether a token accepts deposits Call the List supported tokens operation and set the query parameter token_ids to the token you want to check (for example, ETH_USDT). In the response, read the can_deposit field of the token:
  • true: Deposits are enabled. You can deposit to this token.
  • false: Deposits are currently suspended. Do not send funds.
To check a single token, you can also call Get token information with the token_id path parameter. Both operations accept the optional query parameters wallet_type, wallet_subtype, and chain_ids to narrow the results. Check the status of a deposit you already sent If you have already sent a deposit to a token that was not enabled at the time, do not send further funds to the same address. Instead, confirm the current status of the transfer by calling the List all transactions operation with the following query parameters:
  • types: Deposit.
  • token_ids: The token you deposited, for example ETH_USDT.
  • wallet_ids: The ID of your wallet.
  • transaction_hash (optional): The on-chain transaction hash, to locate a specific transfer.
Read the status field of each returned transaction to determine whether the deposit has been recorded. For sample code that calls this operation, see Option 2: Get transaction status by API call.

Memo and tag requirements

Some chains require a memo or tag in addition to the deposit address so that the deposit can be routed to the correct account, such as XRP, XLM, EOS, ATOM, TON, IOST, BNB Chain, and Hedera. A deposit sent to one of these chains without the required memo or tag, or with an incorrect memo or tag, will fail to match the deposit address and will not be credited automatically. If a deposit on a memo-required chain does not appear in your transaction list, contact [email protected] for assistance. Check whether a chain requires a memo or tag Call the List supported chains operation (or List enabled chains for the chains enabled for your organization) and read the require_memo field of the chain:
  • true: The chain requires a memo or tag for every deposit.
  • false: No memo or tag is required.
To check a single chain, call Get chain information with the chain_id path parameter. Get the memo or tag for a deposit address The memo or tag is bound to the deposit address. When you generate an address on a memo-required chain, the address response includes a memo field. Retrieve it from the response of Create addresses in wallet, or look it up later with List wallet addresses. When you deposit, provide both the address and its memo value from this response, and include the exact memo or tag with every transfer. Confirm a deposit on a memo-required chain To check whether a deposit to a memo-required chain has been credited, call the List all transactions operation with types set to Deposit and wallet_ids set to your wallet ID, then read the status field of each returned transaction.

Internal and contract-triggered transactions

The deposit detection mechanism tracks standard top-level transfers to your deposit addresses. Transfers that are not top-level — such as internal (trace) transfers produced by a contract call, or token movements emitted by a smart contract rather than sent directly to your address — may not be detected or credited automatically. This applies to several chains. If you expect a deposit from this type of transfer and it does not appear, first verify that the transaction was completed on-chain using the relevant blockchain explorer, then use the List all transactions operation to check whether it has been recorded by Cobo. If no record is found, contact [email protected] for assistance.

Deposit troubleshooting

How do I re-check a deposit if I missed its webhook notification?

Webhook notifications can be missed if your endpoint was temporarily unavailable. You do not need to wait for a new notification to confirm a deposit. Query the current state directly with the List all transactions operation, or retrieve a single transfer with the Get transaction information operation. Make sure your webhook endpoint returns a success status code so that future events are delivered reliably; see Introduction to webhooks and callbacks.

What happens to deposits made before a token is listed?

Deposits sent before a token is listed and enabled for deposits may not be detected or credited at the time of the transfer. Before depositing, confirm that the token is enabled as described in Deposit prerequisites. To check whether such a deposit has since been recorded, use the List all transactions operation. If the transaction does not appear, there is no automatic recovery for pre-listing deposits. Contact [email protected] for assistance.

4. Withdraw tokens

Now that you have tokens in your wallet, it’s time to try withdrawing them.

Set up a callback endpoint

To enhance the security of your transactions, it is highly recommended that you set up a callback endpoint to receive and approve withdrawal requests. Once you initiate a withdrawal using the WaaS 2.0 API, the callback endpoint will receive a callback message containing the transaction details. The transaction will proceed only if you approve the withdrawal request. To learn how to set up a callback endpoint and register it on Cobo Portal, refer to Introduction to webhooks and callbacks.

Withdraw tokens

To withdraw tokens from the Asset Wallet, call the Transfer token operation and set the properties in the request body as follows:
  • request_id: Your request ID.
  • source.source_type: Asset.
  • source.wallet_id: The ID of the wallet you have just created.
  • token_id: The ID of the token you want to withdraw.
  • destination.destination_type: Address.
  • destination.account_output: The receiving address and memo (if applicable), and the amount you want to withdraw.
  • category_names: The custom category for you to identify your transactions.
  • description: The description of the transfer.
The response of the withdrawal request is as follows. Record the transaction ID as you will use it in the following steps.

Confirm the withdrawal

If you have set up a callback endpoint, after you initiate the withdrawal transaction, your callback endpoint will receive a message containing the transaction details. Check if the transaction meets expectations, and respond with a success status code (200 or 201) and a response body of ok to approve the transaction. To learn more about handling a callback message, see Set up a callback or webhook endpoint.

Monitor the withdrawal status

In addition to webhook events, you can also call the Get transaction information operation to query the status of the transaction. Set the path parameter transaction_id to the transaction ID returned in the response of the previous withdrawal request.

5. Query wallet balances

After successfully withdrawing tokens from your wallet, you can call List token balances by wallet to query the wallet balances. Specify the path and query parameters as follows:
  • wallet_id: The ID of the wallet you have just created.
  • token_ids: You can leave it empty to query the balances of all tokens, or set it to the specific token you want to query.

6. Sweep funds automatically (auto-sweep)

Auto-sweep automatically consolidates tokens from your deposit addresses into a designated sweep-to address, so that you do not need to move funds out of each deposit address manually. To create an auto-sweep task, call the Create auto-sweep task operation and specify the following:
  • wallet_id: The ID of the wallet you created.
  • token_id: The ID of the token to sweep.
  • min_balance_threshold: (Optional) The minimum token balance an address must hold to be swept. Addresses holding less than this value are skipped, which lets you filter out dust. There is no per-address blocklist; use min_balance_threshold to control the minimum sweep amount.
A sweep moves tokens out of a deposit address, which requires native chain coin to pay for gas. Make sure that gas is available either in the source deposit address or through a configured Fee Station or Auto Fueling. Reaching the deposit threshold alone does not complete a sweep: if no gas is available, the sweep cannot be broadcast. When a sweep cannot proceed, the reason is reported in the failed_reasons array returned by the task details.

Retrieve the swept transactions

The Create auto-sweep task operation returns immediately with a task_id. At this point the task status is Submitted and the transaction_ids array is empty. This is expected and does not indicate a failure. The task transitions to TransactionCreated once it triggers one or more sweep transactions, at which point transaction_ids is populated. To retrieve the transaction IDs, poll the Get auto-sweep task details operation with your task_id until status becomes TransactionCreated.

Timing and lifecycle

Auto-sweep is poll-based rather than instant. A sweep is initiated shortly after its trigger condition is met, so a short delay between the deposit and the sweep transaction is normal. Tasks that cannot proceed do not stay pending indefinitely: a task that remains without gas or without a signature is automatically cancelled after a timeout, and the affected funds remain in the source address so that you can sweep them again later.
For EVM-compatible chains (such as Ethereum and BNB Smart Chain), the same address is used across all EVM chains. As a result, when you list sweep-to addresses with List sweep-to addresses, only one address entry (shown under Ethereum) is returned for all EVM-compatible chains. Do not expect a separate entry for each EVM chain.