Event types
Integration flow
1
Register an endpoint
Create an HTTPS endpoint with the event types you want.
2
Store its signing secret
Retrieve the endpoint-specific
whsec_ value and keep it in a secret manager.3
Verify every delivery
Verify the raw body and
Webhook-* headers before parsing or processing it.4
Persist, acknowledge, and process
Deduplicate on the event
id, durably store it, return 2xx, then do slow work asynchronously.Quickstart
Register and verify your first endpoint.
Endpoint management
Manage URLs, events, and signing secrets.
Events and payloads
Understand identifiers, statuses, and timestamps.
Signatures
Verify Standard Webhooks signatures safely.
Retries
Retry schedule, deduplication, and manual retriggering.
SUBMITTED means the event was accepted for delivery. It does not prove that
every merchant endpoint returned 2xx.