> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rhinestone.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint a signed Swapped widget URL (fiat on-ramp)

> Returns a signed Swapped widget URL the modal embeds in an iframe for the fiat on-ramp. The destination asset is fixed server-side (the configured currency code); the caller supplies the smart account that receives the crypto. `methodSelectionSource: "personalized"` opts a trusted regional selection into strict merchant-catalog validation; fallback, configured, and legacy selections retain exact-method pass-through.



## OpenAPI

````yaml https://raw.githubusercontent.com/rhinestonewtf/openapi/refs/heads/main/deposit-service.json post /onramp/swapped/widget-url
openapi: 3.1.0
info:
  title: Deposit Service API
  version: 1.0.0
  description: >-
    Cross-chain deposit processing service with automatic token bridging and gas
    sponsorship
servers:
  - url: https://v1.orchestrator.rhinestone.dev/deposit-processor
security: []
paths:
  /onramp/swapped/widget-url:
    post:
      tags:
        - Onramp
      summary: Mint a signed Swapped widget URL (fiat on-ramp)
      description: >-
        Returns a signed Swapped widget URL the modal embeds in an iframe for
        the fiat on-ramp. The destination asset is fixed server-side (the
        configured currency code); the caller supplies the smart account that
        receives the crypto. `methodSelectionSource: "personalized"` opts a
        trusted regional selection into strict merchant-catalog validation;
        fallback, configured, and legacy selections retain exact-method
        pass-through.
      parameters:
        - schema:
            type: string
            description: API key for authentication (omit when sending Authorization)
            example: your-api-key
          required: false
          description: API key for authentication (omit when sending Authorization)
          name: x-api-key
          in: header
        - schema:
            type: string
            description: >-
              Bearer platform token (e.g. forwarded by user-service). Takes
              precedence over `x-api-key` when both are present.
            example: Bearer eyJhbGciOi...
          required: false
          description: >-
            Bearer platform token (e.g. forwarded by user-service). Takes
            precedence over `x-api-key` when both are present.
          name: authorization
          in: header
        - schema:
            type: string
            pattern: ^[A-Z]{2}$
            description: >-
              Trusted edge-resolved ISO country. When present it overrides
              body.baseCountry and x-client-ip, and enables country-specific
              payment-method validation.
            example: PH
          required: false
          description: >-
            Trusted edge-resolved ISO country. When present it overrides
            body.baseCountry and x-client-ip, and enables country-specific
            payment-method validation.
          name: x-user-country
          in: header
        - schema:
            type: string
            description: >-
              The end user's IP address as observed by the edge, for edges that
              can name the IP but cannot resolve a country themselves (no local
              GeoIP database). Used only when x-user-country is absent, and
              ignored unless it is a publicly-routable address. Prefer
              x-user-country when your edge already has a country — for example
              Cloudflare's cf-ipcountry — since it needs no lookup here.
            example: 203.0.113.7
          required: false
          description: >-
            The end user's IP address as observed by the edge, for edges that
            can name the IP but cannot resolve a country themselves (no local
            GeoIP database). Used only when x-user-country is absent, and
            ignored unless it is a publicly-routable address. Prefer
            x-user-country when your edge already has a country — for example
            Cloudflare's cf-ipcountry — since it needs no lookup here.
          name: x-client-ip
          in: header
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SwappedWidgetUrlRequestBody'
      responses:
        '200':
          description: Signed widget URL
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SwappedUrlResponse'
        '400':
          description: Invalid request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: Authentication required or invalid credential
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: >-
            API key lacks the required deposits scope, or the account is not
            registered to the calling project
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Server misconfigured or signing failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '503':
          description: Swapped on-ramp is not configured
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  schemas:
    SwappedWidgetUrlRequestBody:
      type: object
      properties:
        smartAccount:
          type: string
          pattern: ^0x[a-fA-F0-9]{40}$
          description: Ethereum address (0x followed by 40 hex characters)
          example: '0x742d35Cc6634C0532925a3b844Bc9e7595f5bE91'
        email:
          type: string
        baseCountry:
          type: string
          pattern: ^[A-Z]{2}$
          description: ISO-3166-1 alpha-2 country code
          example: US
        baseCurrencyCode:
          type: string
          pattern: ^[A-Z]{3,4}$
          description: ISO fiat currency code
          example: USD
        baseCurrencyAmount:
          type: number
          exclusiveMinimum: 0
        locale:
          type: string
        method:
          type: string
          description: >-
            Optional. Preselects a Swapped payment method (a `payment_group`) in
            the widget — e.g. "creditcard", "apple-pay", "bank-transfer",
            "skrill", "pix", "sepa-bank-transfer". Any Swapped-supported value
            is accepted and forwarded as-is; omit it to let Swapped auto-select
            the best method for the user based on their location and other
            signals. See Swapped's Get Payment Methods endpoint for the full,
            per-region list.
          example: apple-pay
        methodSelectionSource:
          type: string
          enum:
            - personalized
            - fallback
            - configured
          description: >-
            How the caller obtained `method`. Use `personalized` only for a
            method rendered from the regional payment-method response; with a
            trusted `x-user-country`, this opts into strict catalog validation.
            `fallback`, `configured`, and omission preserve the legacy
            exact-method pass-through behavior.
          example: personalized
      required:
        - smartAccount
    SwappedUrlResponse:
      type: object
      properties:
        ok:
          type: boolean
          enum:
            - true
        url:
          type: string
        currencyCode:
          type: string
        sandbox:
          type: boolean
        externalCustomerId:
          type: string
        expiresAt:
          type: string
        exchangeFeeBps:
          type: integer
          minimum: 0
      required:
        - ok
        - url
        - currencyCode
        - sandbox
        - externalCustomerId
        - expiresAt
    ErrorResponse:
      type: object
      properties:
        error:
          type: string
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
              code:
                type: string
            required:
              - message
      required:
        - error

````