Skip to main content

Webhooks

Webhooks let your application receive real-time notifications when events occur in Open Pay. Every webhook is signed with ED25519 so you can verify its authenticity.

Configure Your Webhook Endpoint

Register your webhook URL using the API:
Your endpoint must return a 2xx status code within 10 seconds. Any other response is treated as a failure and triggers a retry.

Event Types

Webhook Payload

Every webhook delivery includes these headers: Example payload:

Signature Verification

1

Get the Public Key

Retrieve Open Pay’s ED25519 public key for verification:
Cache the public key in your application. It only rotates during key rotation events, which are announced in advance.
2

Construct the Signed Message

The signed message is the concatenation of the timestamp and the raw request body:
3

Verify the Signature

Verify the ED25519 signature against the signed message using the public key.
4

Validate the Timestamp

Reject any webhook where the timestamp is more than 5 minutes old to prevent replay attacks.

Code Examples

Retry Policy

If your endpoint does not return a 2xx response, Open Pay retries with exponential backoff:
After 5 failed retries, the webhook delivery is marked as failed. You can view failed deliveries and manually retry them from the Merchant Portal or via GET /v1/webhooks/deliveries.

Testing Webhooks

Use the test endpoint to send a sample webhook to your configured URL:
This sends a test payload with dummy data to your webhook URL, signed with the same key used in production. Use it to validate your signature verification logic.
During development, use a tool like ngrok to expose your local server and receive webhooks.

Best Practices

Verify Every Signature

Never process a webhook without verifying the ED25519 signature and checking the timestamp window.

Respond Quickly

Return 200 OK immediately and process the event asynchronously. Webhook delivery times out after 10 seconds.

Handle Duplicates

Use the id field to deduplicate events. The same event may be delivered more than once during retries.

Log Deliveries

Store webhook payloads for debugging. You can also review delivery history at GET /v1/webhooks/deliveries.