Products
Solutions
Developers
Pricing
Company
Get started Sign in

Banks · MFBs · Agent networks

Deposits and withdrawals at the POS, with or without a network.

Your agents take cash in and pay cash out offline. Your app carries an offline purse. Your customers never need a PediWave account. Your core stays the customer's ledger.

For banks, MFBs and agent networks. Integration is a project we scope with your team.

Available to pilot institutions.

The money model

Your core stays the customer's ledger.

Your customers' balances stay in your core. PediWave moves only your float, your agents' floats and the purses you choose to issue, and every movement is between parties who have signed an agreement with us.

The money model Money model. Outside PediWave: your core banking, holding customer accounts. Held by PediWave for your institution: the bank float, customer purses, agent floats and cash-out token liens. You debit the customer in your core and instruct PediWave to issue a purse from your float. A tap to withdraw moves value from a purse to an agent. A cash deposit moves value from the agent's float to your float, and you credit the customer in your core. Cash-out tokens are set aside as a lien on your float and paid to the agent when redeemed. HELD BY PEDIWAVE FOR YOUR INSTITUTION You debit the customer, then instruct PediWave Credit instruction: you credit the customer Issue a purse Tap to withdraw Cash deposit settles Token issued Token redeemed Your core banking Customer accounts Bank float Prefunded by you Customer purses Issued by you, one per device Agent floats One per agent Cash-out token liens Set aside on your float The money model Money model. Outside PediWave: your core banking, holding customer accounts. Held by PediWave for your institution: the bank float, customer purses, agent floats and cash-out token liens. You debit the customer in your core and instruct PediWave to issue a purse from your float. A tap to withdraw moves value from a purse to an agent. A cash deposit moves value from the agent's float to your float, and you credit the customer in your core. Cash-out tokens are set aside as a lien on your float and paid to the agent when redeemed. HELD BY PEDIWAVE Debit, then instruct Credit Issue Token issued Deposit settles Tap to withdraw Redeemed Your core banking Customer accounts Bank float Prefunded by you Customer purses One per device Token liens On your float Agent floats One per agent
PediWave holds funds for the bank and its agents. A purse is the bank's own money, earmarked for one customer's device.
See every posting

All accounts sit in your institution's own isolated environment. Your customers' money in your core is outside it.

Every posting in the bank and agent model
EventWhat movesEffect
You prefund your float A transfer to your float's funding account credits your float Your float up
You issue a purse Your float → the customer's purse, after you debit the customer in your core Your float down, purse up
The customer unloads a purse Purse → your float; you credit the customer in your core Purse down, your float up
A cash deposit settles Agent float → your float, value-dated at the time of the deposit; commission from your float to the agent; you credit the customer in your core Agent float down, your float up
A tap to withdraw settles Purse → the agent; commission from your float to the agent Purse down, agent up
A walk-in withdrawal is approved online Your float → agent float, on your approval; you have already debited the customer in your core Your float down, agent float up
An agent-risk withdrawal is approved at settlement Your float → agent float, value-dated at the time of the withdrawal Your float down, agent float up
An agent-risk withdrawal is declined Nothing moves; the agent carries the loss under your policy None
A cash-out token is issued A lien is placed on your float for the token amount Your available float down, liened up
A cash-out token is redeemed The lien is released and your float pays the agent's float, value-dated at redemption; commission Your float down, agent float up
A cash-out token expires unused The lien is released; you reverse the customer's hold in your core Your available float up
An agent remits cash You record the remittance and your float credits the agent's float Agent float up
An agent is paid out Agent float → the agent's bank account Agent float down

Cash deposit

Take cash deposits with no network. Credit the customer when the agent reconnects.

The customer hands over cash and an account number, or shows a QR code from your app. The agent's terminal checks its deposit limit and the agent's float headroom, signs the deposit, and prints a receipt marked pending. When the terminal reconnects, the deposit settles from the agent's float to your float, value-dated at the time of the deposit. You credit the customer in your core and acknowledge with your core reference.

Because the agent's own float pays for the deposit, a forged deposit only costs the agent. If the float is short at settlement, the deposit waits for a top-up.

Tap to withdraw

Customers with your app withdraw cash with a tap.

A customer with a purse in your app taps the agent's terminal and approves with a PIN. Both devices sign, so the agent can hand over cash with no network. When either side reconnects, the withdrawal settles from the purse to the agent, and PediWave notifies you so you can show it on the customer's statement.

How an offline tap works

Cash-out tokens

Customers without a smartphone withdraw with a one-time code.

While online with you through your own USSD menu, your app or a branch, the customer asks to cash out. You debit or hold the amount in your core and request a cash-out token. PediWave places a lien on your float and returns a signed, single-use code bound to the amount and an expiry. Any of your agents can verify the code and the customer's PIN offline and pay out. The first redemption wins; an unused token expires and the lien is released.

Where your channels do not reach, your policy will be able to allow agent-risk withdrawals against a card with offline PIN verification, up to a cap, once card acceptance is live. You authorise them when the terminal reconnects; a decline is the agent's loss, and the agent's cap tightens automatically.

Card withdrawals at the agent Coming

POST /v1/agent/withdrawals
POST /v1/agent/withdrawals
Authorization: Bearer tk_test_…
Idempotency-Key: wd-0421-20261009-0007
PediWave-Version: 2026-10-01

{
  "amount": 1000000,
  "account_hint": "0123456789",
  "auth_artifact": { "type": "otp_request", "payload": "…" },
  "terminal": "term_01J9…",
  "request_id": "wd-0421-20261009-0007"
}

# → forwarded to your withdrawal_authorisation_route

200 OK
{ "status": "approved", "withdrawal_id": "…",
  "core_reference": "CBK-55188", "receipt": { … } }
Amounts are in kobo: 1000000 is ₦10,000. The bank decides; PediWave moves float only on approval.

Walk-in withdrawals

Walk-in customers are authenticated by you, not by us.

When the terminal is online, it sends the withdrawal to PediWave, which forwards it to your withdrawal authorisation endpoint. You authenticate your customer your way (a one-time code or a prompt on your own USSD menu; card and PIN once cards are live), debit their account and decide. Float moves only on your approval, and the agent pays cash only on an explicit approval. A timeout is never treated as approved: we ask again, and reverse if you approved after the agent gave up.

Your authentication artefact passes through unchanged and is never logged.

Agent floats

Every agent's float, deposits and commission in one view.

Agents prefund their float by transfer to a funding account or at a branch, and remit the cash they collect the same way. Deposits draw on the float, withdrawals and commissions add to it, and commissions are set per agent in basis points. When headroom runs low, the agent is alerted and the terminal tightens deposit acceptance. Each day, float above the agent's ceiling is paid out or kept, as the agent prefers, with a commission statement.

Reconciliation

Reconcile with your core every day, on your own references.

Each day PediWave exports every purse issue and debit, deposit, cash-out token and agent float movement, each with your external reference, the time it happened and its value date. You deliver your core extract as CSV or camt.053; PediWave matches the two on your references. Each break comes with an instruction, and once breaks are resolved the day is certified.

Your app

Your app carries an offline purse, funded from your float.

Add the PediWave Offline SDK to your app in payer mode. Customers you have already verified are registered on your attestation, with no extra one-time code from us. When a customer loads a purse, the request goes to your server; you debit them in your core and instruct PediWave to fund the purse from your float. Their PIN and device key stay in the SDK, so your servers never see them.

Payer mode on the Offline page

Who needs to be registered

Only customers who carry a purse sign up with PediWave.

Who must be registered with PediWave at the point of sale
Person at the POS Registered with PediWave? What identifies them What they can do offline
Your customer with your app and a purse Yes, as a customer with an offline account and a device Device key and a 24-hour identity assertion Tap to pay, tap to withdraw, app-to-app transfer
Your customer with a feature phone No Their account with you and your own authentication; a cash-out token for offline cash Deposit, always; withdraw with a token
Your customer with a card and no phone No Account number for deposits; card and PIN once cards are live (cards coming) Deposit, always; agent-risk card withdrawal where you allow it (cards coming)
Anyone with cash and an account number No The account number (the name is shown only when online, or from your app's QR) Deposit
Your agent Yes, as a sub-merchant with a float, terminals and a collection cap The terminal's credential and key Everything above, within your policy

If you enable it, PediWave keeps a light record for walk-in customers, keyed by a hash of the account number, so support and claims have a history. It is upgraded in place if you later register the customer.

Compliance

What a compliance review will ask, answered plainly.

  • Card data

    Card numbers never reach the PediWave API. Card acceptance is coming, after our PCI DSS certification. When your policy allows agent-risk card withdrawals, the card's cryptogram will be passed to your bank unchanged and never logged. Our PCI DSS status is published on the Security page.

  • Data protection

    Under the NDPA you are the controller for your customers and PediWave is your processor, under a data processing agreement. BVN and NIN are not stored by PediWave; we keep masked values and references, held in-region. Account numbers on deposits are masked once you acknowledge the credit.

  • KYC reliance

    When you register a customer on your own KYC, the attestation is recorded: who attested, the method, your evidence reference and the time. Tiers are capped by agreement, sanctions screening still runs, and a monthly sample is independently re-verified.

  • Licensing

    Your agents remain your agents, under your licence and as your principal. PediWave does not route cash between agent networks of different principals. Details of the licences held by PediWave's operating company are available from our banking team.

Questions from banks.

Do our customers need an app?
No. Customers with a feature phone or a card, and anyone with cash and an account number, can deposit at any agent; withdrawals without an app use a cash-out code obtained from your own channels, such as your USSD menu or a branch, or, once card acceptance is live, a card where you allow agent-risk withdrawals. Your app, with the PediWave Offline SDK, is needed only for customers who carry an offline purse and pay or withdraw with a tap.
How are double-spends handled?
Each flow has its own control. A purse cannot be overdrawn: if a cloned phone signs twice, the second settlement fails and the loss goes where your loss policy says. A cash-out token can be redeemed once: a second redemption is quarantined with both signed redemptions as evidence, a fraud case is opened, and the loss follows your policy. Deposits are paid from the agent's own float, and declined agent-risk withdrawals (cards coming) are the agent's loss, so neither can be abused at your expense.
Who holds the licence?
Your institution holds the licences for your banking and agent business, and your agents operate as your agents. PediWave executes agent cash within your own principal and does not route cash across principals. Our banking team can share details of the licences held by PediWave's operating company.
How do agent floats get funded?
An agent prefunds by transfer to its funding account or by paying in at one of your branches, which you record. Cash the agent collects is remitted the same way. During the day, deposits draw on the float, while withdrawals and commissions add to it. When the float runs low, the agent is alerted and deposit acceptance tightens. Float above the agent's ceiling is paid out daily, or kept, as the agent chooses.
Can we run this in our own tenant?
Yes. An institution with its own customer base runs in its own isolated environment on the ledger, with its own pricing, fraud policy, limits and data. Your float, your agents' floats, your customers' purses and your terminals all live there, and your terminals accept purses issued by you.

Let's design your offline POS flows.

Tell us about your agents, your terminals and your core, and we will map the flows with your team.