What you receive
Every delivery is a POST with the same envelope:
An endpoint registered with an empty event list receives all of them, including events added
later. Name the events explicitly if you would rather opt in deliberately.
Verifying the signature
Every delivery carries atrdrs-signature header:
v1 is an HMAC-SHA256, keyed with your endpoint’s signing secret, over the string
<t>.<raw request body>. The timestamp is inside the signed material, so a captured body cannot be
replayed under a fresh clock.
Verify against the raw bytes you received. Parsing the JSON and re-serializing it will change
the whitespace and the signature will not match.
Retries, and what your handler owes us
Answer2xx and the delivery is done. Anything else, including a timeout, is a failure and we try
again: after 1 minute, 5 minutes, 30 minutes, 2 hours, and 6 hours. That is six attempts across
roughly nine hours, which carries a receiver through a deploy or a short outage. After the last
attempt the delivery is marked failed and stays in the delivery log for you to read.
Two consequences worth designing for:
Answer fast, work later. We wait five seconds for a response. Acknowledge the delivery, then do
your processing on your own time. A handler that does its work before responding will time out and
be retried even though it succeeded.
Handle duplicates. Because a timeout is indistinguishable from a failure, a retry can deliver an
event your handler already processed. Every payload carries a natural key for this: referenceId on
balance and reset events, registrationId on registration events, accountNumber on risk events. Key your
processing on those rather than assuming each delivery is new.
We refuse to dial private or reserved addresses, and we do not follow redirects. Point the endpoint
at its real public URL.
When something is not arriving
POST /api/partner/webhooks/test sends a signed ping to one of your endpoints immediately and
reports exactly what your server answered, which separates “our delivery is broken” from “your
handler rejected it.”
GET /api/partner/webhooks/deliveries is the log: every delivery for an endpoint, newest first,
with its status, attempt count, the HTTP status your server returned, and the last error. Terminal
deliveries are kept for 60 days. A delivery still pending retry is never aged out.
The live routes are in API Reference under Webhooks.