A non-custodial payment provider moves your money without holding it between payments. Who controls the funds, who carries the risk, and what to ask.
A non-custodial payment is one where the provider moves and converts your money without holding a balance of it on your behalf. Funds stay in a bank account or wallet you control until the moment a payment executes. If the payment can't complete, they go back where they started. A custodial provider, by contrast, keeps your money in its own accounts between payments, which quietly turns its balance sheet into your risk.
That risk isn't theoretical. When the banking-as-a-service middleware company Synapse filed for bankruptcy in April 2024, end users of the fintech apps built on it were owed about $265 million and lost access to it for months. The court-appointed trustee found the partner banks held about $180 million of that, and later put the shortfall at roughly $65 million to $95 million. Nobody had to steal anything. The records of who owned which dollars in the pooled accounts simply didn't reconcile.
For fintechs, PSPs, and payroll platforms that move customer money, where the funds sit between payments is a design decision with regulatory, audit, and balance-sheet consequences.
Three questions separate the two models.
A useful way to picture it: a custodial provider works like a parking garage. Your car sits on their property between trips, and if the garage goes bust, getting it out is a legal process. A non-custodial provider works like a toll road. Your car is only on their road while it's moving, and it's yours the whole time.
| Custodial | Non-custodial | |
|---|---|---|
| Fund control | Provider holds balances on your behalf | You hold funds until each payment executes |
| Failure handling | Funds stay in the provider's balance and are credited back there | Funds return to the originating account or wallet |
| Counterparty risk | Every balance held by the provider | Only the payment in flight |
| If the provider fails | Balances frozen pending reconciliation | Unsent funds unaffected |
| Reconciliation | Your ledger against the provider's internal ledger | Your ledger against bank statements and on-chain records |
| Typical use cases | Consumer wallets, stored-value apps, exchanges | B2B payouts, payroll, remittance, treasury |
Custody isn't wrong. It's a trade. Custodial balances make instant internal transfers and a simple "wallet" UX easy, and plenty of products need that. The point is to choose it deliberately, per use case, rather than inherit it from whichever provider you picked.
BlindPay is a non-custodial payment processor. In the docs' own words, it never takes custody of your stablecoins beyond the single transaction it is asked to execute (overview). Here's what that looks like in a payout from a customer-controlled wallet:
approve on Ethereum, Base, Polygon, or Arbitrum, a signed XDR on Stellar, or a token delegation on Solana.refunded and the stablecoins go back to the same wallet that authorized it.One precise distinction worth knowing: a payout that ends failed, for example because a compliance check rejected it, does not refund automatically. It needs a follow-up with support (payouts). The automatic return covers what the bank rejects or sends back.
On the way in, a payin works the same way in reverse. A bank deposit is converted at the quoted rate and delivered straight to the destination wallet, rather than sitting in a provider balance. The full sequence is in how a stablecoin payment works.
BlindPay also offers managed wallets, in beta. Those are custodied by BlindPay, for teams that want a balance held between on-ramp and off-ramp without running their own wallet. It's an explicit choice made per customer, not the default.
Fintechs, PSPs, and payroll platforms moving customer money get asked the same questions by partner banks, auditors, and regulators: where are customer funds at any moment, in whose name, and can you prove it?
A non-custodial setup makes those answers shorter:
Regulation is moving the same direction. The US GENIUS Act, signed in July 2025, requires payment stablecoin issuers to hold one-for-one reserves and gives holders priority over those reserves if an issuer fails. That protects the token. It doesn't cover the provider in between, which is why the custody model of your payment provider still deserves its own review.
"Non-custodial" appears on a lot of websites. These six questions tell you whether it describes the product:
A provider that answers all six in writing, with the same answers its docs give, is non-custodial. One that needs a follow-up call for question 1 probably isn't.
Map where your customers' money actually sits today, hop by hop, from their bank account to the recipient's. Every hop where a third party holds a balance is a place to ask the questions above. Then read BlindPay's flow of funds in the docs and trace a test payout on a free development instance, where a payout quote for $777.00 is forced to end refunded, so you can watch the return land back in the wallet. The payout quickstart covers the setup.
This article is for general information only and is not legal, tax, or financial advice.
AP2, ACP, and x402 each verify that an AI agent had permission to spend. Here is what every protocol covers, who backs it, and the reconciliation gap none of them close.
Seven stablecoin payment platforms compared for US fintechs in 2026: what makes an API production-ready, how each provider handles compliance, settlement speed against ACH, and how to run the evaluation.
How to choose a stablecoin payment provider in 2026: the four provider types, a comparison of 10 options, and the questions that decide the fit.