Webhooks
A collection was paid
Sent to your webhook endpoints when a collection succeeds. Verify the
NuruPay-Signature header before trusting the body. Delivery is
at-least-once and unordered: deduplicate on id and fetch the object
for its current state if order matters. Respond with any 2xx within 10s;
otherwise NuruPay retries after 1m, 5m, 30m, 2h, 6h, and 12h.
Header Parameters
NuruPay-Signature*string
t=<unix seconds>,v1=<hex HMAC-SHA256(signing_secret, "<t>.<raw body>")>. Reject if the signature does not match or t is more than 5 minutes old.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
Example Requests
POST
/collection.succeeded