# Platform and billing

## Dashboard

[dashboard-ika-accounts.mpckit.xyz](https://dashboard-ika-accounts.mpckit.xyz) is where you manage your platform:

- **Overview**: balance, transactions and spend over time, recent activity.
- **Users**: every account created through your platform.
- **Activity**: each transaction with its status and cost.
- **API keys**: create and revoke keys.
- **Billing**: top-ups and charges.
- **Settings**: allowed origins, webhook URL, team members.

## Billing

Billing is prepaid in US dollars.

1. **Top up** by sending USDC or SUI on Sui to the treasury address shown under Billing, from a wallet registered to your platform. It is credited automatically.
2. **Each sponsored transaction** is charged its actual cost, Sui gas and Ika fees, converted at current prices, plus a **0.3% markup**.
3. **When the balance runs low**, new transactions are refused with `insufficient_platform_balance`. The dashboard shows how many transactions your balance still covers.

Deposits and withdrawals through the funds panel are paid by the user, inside the bridge quote, not from your balance.

## Webhooks

Set a URL in Settings to receive events:

| Event | When |
|---|---|
| `transaction.updated` | a transaction changes status |
| `bridge.order.updated` | a deposit or withdrawal changes status |
| `account.updated` | an account is created or activated |

Each request carries `x-ika-accounts-timestamp` and `x-ika-accounts-signature: sha256=<hex>`, an HMAC-SHA256 of `timestamp + "." + rawBody` with your webhook secret. Verify it, and reject timestamps older than 5 minutes. Failed deliveries are retried with backoff for about 7 hours.

```ts
import { createHmac, timingSafeEqual } from 'node:crypto';

function verify(rawBody: string, timestamp: string, header: string, secret: string) {
  const expected = createHmac('sha256', secret).update(`${timestamp}.${rawBody}`).digest('hex');
  const age = Date.now() / 1000 - Number(timestamp);
  return age < 300 && timingSafeEqual(Buffer.from(header), Buffer.from(`sha256=${expected}`));
}
```

Webhook URLs must be public HTTPS endpoints.

## Limits

| Limit | Default |
|---|---|
| Sponsored transactions per user per day | 200 |
| Sponsored transactions per platform per day | 5,000 |
| New accounts per platform per day | 200 |
| Transactions in flight per user | 3 |
| API requests per user per minute | 60 |
| Raw message size | 4,096 bytes |

Hitting a limit returns `rate_limited`. Ask us to raise them for a launch.
