Webhooks
Webhooks let your application receive real-time notifications when events occur in Open Pay. Every webhook is signed with ED25519 so you can verify its authenticity.Configure Your Webhook Endpoint
Register your webhook URL using the API:Your endpoint must return a
2xx status code within 10 seconds. Any other response is treated as a failure and triggers a retry.Event Types
Webhook Payload
Every webhook delivery includes these headers:
Example payload:
Signature Verification
1
Get the Public Key
Retrieve Open Pay’s ED25519 public key for verification:
2
Construct the Signed Message
The signed message is the concatenation of the timestamp and the raw request body:
3
Verify the Signature
Verify the ED25519 signature against the signed message using the public key.
4
Validate the Timestamp
Reject any webhook where the timestamp is more than 5 minutes old to prevent replay attacks.
Code Examples
- TypeScript
- Go
Retry Policy
If your endpoint does not return a2xx response, Open Pay retries with exponential backoff:
Testing Webhooks
Use the test endpoint to send a sample webhook to your configured URL:Best Practices
Verify Every Signature
Never process a webhook without verifying the ED25519 signature and checking the timestamp window.
Respond Quickly
Return
200 OK immediately and process the event asynchronously. Webhook delivery times out after 10 seconds.Handle Duplicates
Use the
id field to deduplicate events. The same event may be delivered more than once during retries.Log Deliveries
Store webhook payloads for debugging. You can also review delivery history at
GET /v1/webhooks/deliveries.