If you are using Payment Request APIs, we suggest using the “webhook” parameter and webhook v1

Overview

HitPay provides event webhooks that are HTTP post requests triggered after key events that happen on the hitpay platform. These webhooks can be used to build your own automation and processes.

List of Events

These are the list of events you can listen to

Event NameWhen does it trigger?
charge.createdOnce a payment is successfully completed
charge.updatedOnce a payment is refunded / partially refunded
payout.createdOnce a payout is successfully completed
order.createdOnce an order is created successfully
order.updatedOnce an order status is updated
invoice.createdOnce the invoice is created
transfer.createdOnce the transfer is created
transfer.updatedOnce the transfer is updated

Register Your Webhook

The first thing you need to do before you can receive the webhook is to register the URL. Navigate to “API Keys” and enter the name and the URL you wish to receive the webhook.

Webhook Payload

Headers that are included in the webhook HTTP POST request

HTTP headerdetails
Hitpay-SignatureSHA 256 of the JSON payload. Derived from the salt value
Hitpay-Event-Typecreated / updated based on the event
Hitpay-Event-ObjectThe type of object. It can be charge/payout/invoice/order
User-AgentHitPay v2.0

HTTP request body is a JSON object and the object structure can be any of the above 4 types. Refer to the header value Hitpay-Event-Objectto determine the object type

Validating Webhook

To validate a Hitpay-Signature:

  1. Collect Data: Receive the JSON payload and the Hitpay-Signature from the incoming request.
  2. Prepare Key: Use your pre-shared salt value as the secret key.
  3. Compute HMAC: Generate an HMAC using the SHA-256 algorithm, the JSON payload as the data, and your salt as the key.
  4. Compare Signatures: Compare the computed HMAC to the Hitpay-Signature received. If they match, the request is valid and has not been tampered with.