WestwyrdWestwyrd/integration
VenturesIntegration
COUNTERPARTY INTEGRATION · INSTITUTIONAL ONBOARDING

Integration
Requirements

Westwyrd integration is a structured four-phase process designed to ensure that counterparties meet technical, legal, and operational requirements before accessing production settlement infrastructure. All phases are sequential and each must be completed before the next begins.

4-PHASE PROCESSTECHNICAL REVIEWSTAGING ENVIRONMENTPRODUCTION ACCESSKYC/AMLAPI INTEGRATION
Phases
4
Timeline
4–8 weeks
API Version
v2.3
Auth
HMAC-SHA256
Environments
Staging+Prod
Support
4h SLA
FIGURE 01
INTEGRATION PHASES FLOW
1
APPLICATION
2–3 DAYS
Identity docs
Use case review
NDA execution
2
TECHNICAL REVIEW
5–7 DAYS
API spec review
Architecture review
Security questionnaire
3
STAGING
2 WEEKS
Integration testing
Load testing
Security verification
4
PRODUCTION
ONGOING
Live credentials
Monitoring setup
SLA active
01MANDATORY REQUIREMENTS

All institutional counterparties must complete four sequential integration phases. No partial or accelerated access is available. Each phase is a prerequisite for the next — the protocol enforces this sequentially at the integration management layer, and production credentials are issued only upon confirmed completion of all prior phases.

Technical requirements are non-negotiable: dedicated server infrastructure with no shared hosting, TLS 1.3 for all API connections, and HMAC-SHA256 authentication with time-bounded nonces. These requirements exist because the settlement protocol's security model assumes that counterparty infrastructure is hardened — a compromised integration endpoint represents a systemic risk, not just a per-counterparty risk.

Legal requirements run parallel to technical onboarding. A signed Master Service Agreement must be in place before any staging environment access is granted. KYC/AML documentation per applicable jurisdiction must be completed and verified by Westwyrd's compliance function. A designated technical contact must be identified as the primary point of contact for the integration lifecycle.

MANDATORY TECHNICAL REQUIREMENTS
InfraDedicated server (no shared hosting)
TLS1.3 minimum
AuthHMAC-SHA256
NonceTime-bounded (5min window)
Rate Limit1000 req/min
Key RotationPer-epoch supported
02FOUR-PHASE PROCESS
01
2–3 DAYS
APPLICATION
Organizational identity documentation
Use case description and intended transaction volume
Jurisdiction declaration
NDA execution

The application phase establishes organizational identity and use case legitimacy. Submissions are reviewed for completeness within one business day and assessed for fit within two additional days. Accepted applicants proceed to technical review. Rejected applicants receive written rationale with reapplication eligibility.

02
5–7 BUSINESS DAYS
TECHNICAL REVIEW
Architecture documentation submission
API integration spec review
Security questionnaire completion
Key management plan review

The Westwyrd engineering team reviews the counterparty's technical architecture for compatibility with protocol requirements. The review covers integration design, security practices, cryptographic implementation, and operational procedures. Custom circuit components receive a formal verification review.

03
2 WEEKS
STAGING INTEGRATION
Full API access on staging environment
Integration test suite completion
Load testing: minimum 10k transactions
Security verification by Westwyrd team

Staging provides a production-equivalent environment including chain state, contract deployments, and observability infrastructure. Counterparties run the complete integration test suite, execute load testing to verify rate limit behavior, and complete a security review. Minimum 14-day period with no exceptions.

04
ONGOING
PRODUCTION ACCESS
Live API credentials issued
Dedicated support channel activated
Monitoring dashboard access
SLA active from first production transaction

Production access is granted through a governance transaction that adds counterparty addresses to the settlement contract whitelist. Requires 3-of-5 multisig authorization. Post-activation monitoring runs for 30 days with enhanced alerting thresholds before transitioning to standard SLA parameters.

03REJECTION & SUSPENSION CRITERIA
REJECTION CRITERIA
01Inability to demonstrate adequate key management infrastructure
02Regulatory jurisdiction where protocol operation is prohibited
03Incomplete or fraudulent KYC/AML documentation
04Failure to complete staging test suite with >99.5% success rate
SUSPENSION CRITERIA
01Detected attempt to probe or exploit protocol vulnerabilities
02Violation of API rate limits (repeated)
03Breach of MSA terms including data handling requirements
04Regulatory notification requiring suspension
SUSPENSION POLICY

Suspension is immediate for confirmed security violations. Other causes allow 72-hour cure period with written notice.