Webhooks

Webhooks deliver signed event notifications to the HTTPS endpoint registered for your partner integration.

Receiver requirements

  1. Read the raw request body before parsing JSON.
  2. Verify the signature with the webhook signing key issued for the endpoint.
  3. Reject stale or invalid signatures.
  4. Deduplicate events by their stable event identifier.
  5. Return a successful response only after the event is safely accepted for processing.
  6. Process retries idempotently and out of the request path when appropriate.

Never log signing keys, authentication tokens or customer personal information. Rotate a compromised secret through the authorised operational process.