Webhooks
Webhooks deliver signed event notifications to the HTTPS endpoint registered for your partner integration.
Receiver requirements
- Read the raw request body before parsing JSON.
- Verify the signature with the webhook signing key issued for the endpoint.
- Reject stale or invalid signatures.
- Deduplicate events by their stable event identifier.
- Return a successful response only after the event is safely accepted for processing.
- Process retries idempotently and out of the request path when appropriate.
Never log signing keys, authentication tokens or customer personal information. Rotate a compromised secret through the authorised operational process.