Webhooks
- get/v1/webhook_endpointsList webhook endpoints for the current mode
- post/v1/webhook_endpointsRegister a webhook endpoint
- post/v1/webhook_endpoints/{id}/disableStop sending to an endpoint
- post/v1/webhook_endpoints/{id}/enableStart sending to a disabled endpoint again
- post/v1/webhook_endpoints/{id}/deleteDelete an endpoint
- get/v1/eventsList events and their delivery status
- post/v1/events/{id}/redeliverSend an event again to its endpoints
List webhook endpoints for the current mode
get/v1/webhook_endpoints
curl https://sandbox.api.biftpay.com/v1/webhook_endpoints \
-H "Authorization: Bearer bp_test_..."Responses
- 200Webhook endpointsobject
Fields
object"list"requireddataarray of WebhookEndpointrequiredFields of data
idstring (uuid)requiredobject"webhook_endpoint"requiredlivemodebooleanrequiredurlstring (uri)requiredeventsarray of payment_intent.successful | payment_intent.failed | payment_intent.abandoned | payment_intent.canceled | refund.succeeded | refund.failed | payout.paid | payout.failed | payout.canceled | dispute.created | dispute.won | dispute.lost | invoice.paid | crypto_payout.paid | crypto_payout.failedrequiredstatusenabled | disabledrequiredcreated_atstring (date-time)requiredhas_morebooleanrequired
Register a webhook endpoint
post/v1/webhook_endpoints
The signing secret is returned once, here. URLs must be https with a public
hostname. Each delivery has headers Biftpay-Event-Id, Biftpay-Timestamp and
Biftpay-Signature: t=<unix seconds>,v1=<hex HMAC-SHA256 of "<t>.<event id>.<body>">.
Recompute it with the secret, compare in constant time and reject anything older
than 5 minutes. Failed deliveries retry after 1m, 5m, 30m, 2h, 6h and 12h.
Parameters
Idempotency-Keystringin headerrequiredA unique key per logical request, for example a UUID. Up to 255 characters.
up to 255 characters
Body
urlstring (uri)requiredeventsarray of payment_intent.successful | payment_intent.failed | payment_intent.abandoned | payment_intent.canceled | refund.succeeded | refund.failed | payout.paid | payout.failed | payout.canceled | dispute.created | dispute.won | dispute.lost | invoice.paid | crypto_payout.paid | crypto_payout.failedOmit or leave empty for every event type.
curl -X POST https://sandbox.api.biftpay.com/v1/webhook_endpoints \
-H "Authorization: Bearer bp_test_..." \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{
"url": "https://merchant.example.com/biftpay/webhooks"
}'Responses
- 201Createdobject
Fields
idstring (uuid)requiredobject"webhook_endpoint"requiredlivemodebooleanrequiredurlstring (uri)requiredeventsarray of payment_intent.successful | payment_intent.failed | payment_intent.abandoned | payment_intent.canceled | refund.succeeded | refund.failed | payout.paid | payout.failed | payout.canceled | dispute.created | dispute.won | dispute.lost | invoice.paid | crypto_payout.paid | crypto_payout.failedrequiredstatusenabled | disabledrequiredcreated_atstring (date-time)requiredsecretstringrequired - 400Invalid request
Stop sending to an endpoint
post/v1/webhook_endpoints/{id}/disable
Parameters
idstring (uuid)in pathrequiredIdempotency-Keystringin headerrequiredA unique key per logical request, for example a UUID. Up to 255 characters.
up to 255 characters
curl -X POST https://sandbox.api.biftpay.com/v1/webhook_endpoints/{id}/disable \
-H "Authorization: Bearer bp_test_..." \
-H "Idempotency-Key: $(uuidgen)"Responses
- 200The disabled endpointWebhookEndpoint
Fields
idstring (uuid)requiredobject"webhook_endpoint"requiredlivemodebooleanrequiredurlstring (uri)requiredeventsarray of payment_intent.successful | payment_intent.failed | payment_intent.abandoned | payment_intent.canceled | refund.succeeded | refund.failed | payout.paid | payout.failed | payout.canceled | dispute.created | dispute.won | dispute.lost | invoice.paid | crypto_payout.paid | crypto_payout.failedrequiredstatusenabled | disabledrequiredcreated_atstring (date-time)required - 404Not found, or not visible to this key
Start sending to a disabled endpoint again
post/v1/webhook_endpoints/{id}/enable
New events go to it from now. Send ones it missed with POST /v1/events/{id}/redeliver.
Parameters
idstring (uuid)in pathrequiredIdempotency-Keystringin headerrequiredA unique key per logical request, for example a UUID. Up to 255 characters.
up to 255 characters
curl -X POST https://sandbox.api.biftpay.com/v1/webhook_endpoints/{id}/enable \
-H "Authorization: Bearer bp_test_..." \
-H "Idempotency-Key: $(uuidgen)"Responses
- 200The enabled endpointWebhookEndpoint
Fields
idstring (uuid)requiredobject"webhook_endpoint"requiredlivemodebooleanrequiredurlstring (uri)requiredeventsarray of payment_intent.successful | payment_intent.failed | payment_intent.abandoned | payment_intent.canceled | refund.succeeded | refund.failed | payout.paid | payout.failed | payout.canceled | dispute.created | dispute.won | dispute.lost | invoice.paid | crypto_payout.paid | crypto_payout.failedrequiredstatusenabled | disabledrequiredcreated_atstring (date-time)required - 400Invalid request
- 404Not found, or not visible to this key
Delete an endpoint
post/v1/webhook_endpoints/{id}/delete
Nothing more is sent to it, including deliveries still waiting, and it leaves the list. Its past deliveries stay in the event history. This can't be undone; add the URL again to get a new endpoint (with a new signing secret).
Parameters
idstring (uuid)in pathrequiredIdempotency-Keystringin headerrequiredA unique key per logical request, for example a UUID. Up to 255 characters.
up to 255 characters
curl -X POST https://sandbox.api.biftpay.com/v1/webhook_endpoints/{id}/delete \
-H "Authorization: Bearer bp_test_..." \
-H "Idempotency-Key: $(uuidgen)"Responses
- 200Deletedobject
Fields
idstringrequiredobject"webhook_endpoint"requireddeletedtruerequired - 404Not found, or not visible to this key
List events and their delivery status
get/v1/events
Parameters
limitintegerin query1 to 100 · default 20
starting_afterstring (uuid)in queryThe id of the last item on the previous page.
typepayment_intent.successful | payment_intent.failed | payment_intent.abandoned | payment_intent.canceled | refund.succeeded | refund.failed | payout.paid | payout.failed | payout.canceled | dispute.created | dispute.won | dispute.lost | invoice.paid | crypto_payout.paid | crypto_payout.failedin querycurl https://sandbox.api.biftpay.com/v1/events \
-H "Authorization: Bearer bp_test_..."Responses
- 200A page of eventsEventList
Fields
object"list"requireddataarray of EventrequiredFields of data
idstring (uuid)requiredobject"event"requiredtypepayment_intent.successful | payment_intent.failed | payment_intent.abandoned | payment_intent.canceled | refund.succeeded | refund.failed | payout.paid | payout.failed | payout.canceled | dispute.created | dispute.won | dispute.lost | invoice.paid | crypto_payout.paid | crypto_payout.failedrequiredlivemodebooleanrequiredcreated_atstring (date-time)requireddataobjectrequiredFields of data
objectobjectrequiredThe payment, payout or refund as it was at that moment.
deliveriesarray of objectFields of deliveries
endpoint_idstring (uuid)statuspending | delivered | retrying | failedattemptsintegerlast_response_statusinteger | nullhas_morebooleanrequired
Send an event again to its endpoints
post/v1/events/{id}/redeliver
Parameters
idstring (uuid)in pathrequiredIdempotency-Keystringin headerrequiredA unique key per logical request, for example a UUID. Up to 255 characters.
up to 255 characters
curl -X POST https://sandbox.api.biftpay.com/v1/events/{id}/redeliver \
-H "Authorization: Bearer bp_test_..." \
-H "Idempotency-Key: $(uuidgen)"Responses
- 200How many deliveries were queuedobject
Fields
object"event_redelivery"event_idstringqueuedinteger