Webhooks
Real-time notifications your server receives when something happens — and the exact data shape of every event.
A webhook is how PaymentGateway tells your server that something happened — a payment succeeded, a refund settled, a subscription renewed — the moment it happens, instead of you polling for it. You register a URL on your server, pick which events you care about, and the platform posts each one to that URL as it occurs.
Where to get one
Register an endpoint from the dashboard, or via the API:
curl "$WALLET/webhook_endpoints/" \
-H "Authorization: Bearer ${SECRET_KEY}" \
-H "Content-Type: application/json" \
-d '{
"url": "https://your-app.example/webhooks",
"enabled_events": ["charge.paid", "refund.created", "invoice.paid"]
}'- The URL must be public HTTPS.
enabled_eventsis an allowlist — only the event names you list (or"*"for everything) are delivered.- You get a signing secret back, shown once — use it to verify each delivery is really from PaymentGateway.
- Delivery is at-least-once: build your handler to safely process the same event twice.
See Webhooks for signature verification, the retry schedule, and other delivery mechanics. This page focuses on what data you actually receive.
The shape of every event
{
"event": "charge.paid",
"data": { "...": "the resource this event is about" },
"timestamp": "2026-07-25T17:20:00Z"
}event tells you what happened, data is the object it happened to (usually the same
shape you'd get back from the matching GET endpoint), and timestamp is when it
occurred. What's inside data differs by event — that's what the rest of this page
covers, grouped by feature area.