Webhooks are the recommended way to react to RabbitPay events in your backend. Rather than polling, RabbitPay POSTs a signed JSON payload to your endpoint when something interesting happens.
Register an endpoint
Create a webhook endpoint in the Dashboard → Developers → Webhooks, or via API:
Event types
Example payload
Verifying signatures
Every webhook includes a RabbitPay-Signature header:
Compute the HMAC-SHA256 of t.body using your endpoint’s signing secret (whsec_...) and compare in constant time.
Reject requests older than 5 minutes based on the t timestamp to prevent replay attacks.
Retries
RabbitPay retries failed deliveries with exponential backoff for 72 hours:
- 1st retry: 1 minute
- 2nd: 5 minutes
- 3rd: 30 minutes
- 4th–10th: 1, 2, 4, 8, 12, 24, 48 hours
Your endpoint should return 2xx within 5 seconds. Anything else is treated as a failure.
Debugging
Use the Dashboard → Developers → Webhook attempts to inspect every delivery, replay events, or download the raw payload for local testing.