Configure Webhooks
Create, update, and delete payment notification webhooks.
Configure where DigetPay sends payment notifications for your merchant account, including payment success, failure, capture, and refund events.
After configuring your webhook, implement your endpoint using Receiving Webhooks.
Webhooks are the recommended way to receive server-to-server payment updates. Do not rely on customer redirect URLs alone to confirm payment status.
Merchant Portal (UI)
The easiest way to configure a webhook is through the DigetPay Merchant Portal.
- Log in to the DigetPay Merchant Portal.
- Navigate to Settings → Webhooks.
- Add your HTTPS endpoint URL.
- Configure the required webhook settings.
- Save the configuration.
- Complete a test transaction and verify that your endpoint receives the notification.
Important: Your webhook URL must use HTTPS and be publicly reachable from the internet.
Webhook Configuration Flow
sequenceDiagram
autonumber
participant Merchant as Merchant
participant Portal as DigetPay Merchant Portal
participant Config as Webhook Configuration
Merchant->>Portal: Add webhook URL and settings
Portal->>Config: Validate and save configuration
Config-->>Portal: Configuration saved
Portal-->>Merchant: Webhook configured
Create a Webhook
Webhooks can also be managed programmatically through the Merchant Portal API.
Request
POST /merchant/account/webhooksRequest Payload
{
"url": "https://yourstore.com/webhooks/digetpay",
"events": [
"sale.approved",
"refund.completed"
],
"active": true
}Sequence
sequenceDiagram
autonumber
participant Merchant as Merchant API Client
participant API as DigetPay Portal API
participant Config as Webhook Configuration
Merchant->>API: POST /merchant/account/webhooks
API->>Config: Validate and save webhook
Config-->>API: Configuration saved
API-->>Merchant: 201 Created
Success Response
{
"success": {
"status": 201,
"body": {
"id": "wh_abc123",
"url": "https://yourstore.com/webhooks/digetpay",
"events": [
"sale.approved",
"refund.completed"
],
"active": true
}
}
}Invalid Request Response
{
"failed": {
"status": 400,
"body": {
"statusCode": 400,
"message": "Invalid webhook URL",
"error": "Bad Request"
}
}
}Unauthorized Response
{
"failed_unauthorized": {
"status": 401,
"body": {
"statusCode": 401,
"message": "Unauthorized",
"error": "Unauthorized"
}
}
}For webhook payload handling, event details, and transaction processing, see Receiving Webhooks.
Update a Webhook
Use the webhook ID returned when the webhook was created.
Request
PUT /merchant/account/webhooks/{webhookId}Request Payload
{
"url": "https://yourstore.com/webhooks/digetpay-v2",
"active": true
}Sequence
sequenceDiagram
autonumber
participant Merchant as Merchant API Client
participant API as DigetPay Portal API
participant Config as Webhook Configuration
Merchant->>API: PUT /merchant/account/webhooks/{webhookId}
API->>Config: Validate and update configuration
Config-->>API: Configuration updated
API-->>Merchant: 200 Updated webhook
Delete a Webhook
Use the webhook ID associated with the endpoint you want to remove.
Request
DELETE /merchant/account/webhooks/{webhookId}Sequence
sequenceDiagram
autonumber
participant Merchant as Merchant API Client
participant API as DigetPay Portal API
participant Config as Webhook Configuration
Merchant->>API: DELETE /merchant/account/webhooks/{webhookId}
API->>Config: Remove webhook configuration
Config-->>API: Configuration deleted
API-->>Merchant: 204 No Content
Important: Deleting a webhook stops payment notifications from being sent to that URL. Make sure your integration is updated before deleting a production webhook.
Callback URL for S2S Integrations
For server-to-server integrations, DigetPay forwards supported gateway notifications to the merchant callback URL configured for the integration.
Example callback configuration:
{
"method": "POST",
"url": "https://yourstore.com/webhooks/digetpay",
"contentType": "application/json"
}For S2S payment flows, DigetPay receives gateway callbacks through the relevant callback endpoint:
POST /v1/payment/s2s/callback/{merchantId}For payload handling and transaction verification, see Receiving Webhooks.
Portal API Access
The Portal API requires a Portal Bearer Token for authentication.
Before using the webhook management endpoints, make sure you have completed the Portal API authentication flow.
For details on:
- Obtaining a Portal Bearer Token
- Authenticating with the Merchant Portal
- Using the
Authorization: Bearer <token>header - Token expiration and re-authentication
- Credential security and environment separation
see Authentication & Credentials.
Important: The Portal Bearer Token and Payment API Key are different credentials. Use the Portal Bearer Token with Merchant Portal APIs and the Payment API Key (
x-api-key) with Payment APIs.
Authorization Header
Include the Portal Bearer Token in requests to protected Portal API endpoints:
Authorization: Bearer YOUR_PORTAL_TOKENPortal API Endpoints
| Action | Method | Path |
|---|---|---|
| List webhooks | GET | /merchant/account/webhooks |
| Create webhook | POST | /merchant/account/webhooks |
| Update webhook | PUT | /merchant/account/webhooks/{id} |
| Delete webhook | DELETE | /merchant/account/webhooks/{id} |
Staging vs Production
Register separate webhook URLs or separate paths for each environment.
| Environment | Configuration |
|---|---|
| Fin staging | Use staging credentials, staging webhook URLs, and test transactions. |
| Production | Use production credentials, production webhook URLs, and live transactions. |
Important: Keep staging and production webhook configurations separate. Do not allow staging events to update production orders, refunds, or transaction records.
Webhook Management Checklist
Before using a webhook in production, verify that:
- The endpoint uses HTTPS.
- The endpoint is publicly reachable.
- The server accepts
POSTrequests. - The endpoint accepts
application/json. - The webhook is registered under the correct merchant account.
- The webhook is configured in the correct environment.
- The endpoint returns HTTP
200within the expected response time. - Incoming events are logged for troubleshooting.
- Duplicate events are handled safely.
- Transaction status is confirmed using the documented webhook or status verification process.
Related Guides
Implement your server-side webhook receiver and process incoming events.
Review webhook validation and security requirements.
Learn how to obtain and use Payment API Keys and Portal Bearer Tokens.
Review webhook event fields and status mapping.
Updated 22 days ago

