Webhooks

Handling order

  1. 1
    Parse the JSON

    Keep order number, status, signature, and business fields.

  2. 2
    Recompute and compare the signature

    Use fields marked signable on the callback page and recompute with HMAC-MD5 using appSecret.

  3. 3
    Update by merchant order

    Locate by merchant order number. If the same final state arrives again, return the JSON acknowledgement. Do not fulfill or post again.

  4. 4
    Respond with JSON after durable success

    Return {"status":"success"} / {"status":"SUCCESS"} only after verification and the business update succeed.

Acknowledgement and retries

Respond with JSON {"status":"success"} / {"status":"SUCCESS"}. After the first failure, retries occur at 10, 60, and 600 seconds — up to three more attempts.