Docs

Documentation sections

Webhooks

Register an HTTPS endpoint. LaxoPay posts JSON when a test payment or customer changes. Each endpoint has a signing secret.

POST /v1/webhook_endpoints
{"url":"https://example.com/webhooks/laxopay"}

Events: payment.succeeded, payment.failed, payment.authorized, payment.refunded, customer.created.

The body is an event object. data.object is the payment or the customer. The header is:

LaxoPay-Signature: t=1710000000,v1=hex

v1 is HMAC-SHA256 of timestamp + "." + raw_body, using the endpoint secret, hex encoded. Compare with a constant-time function. Use the raw body, not a re-serialized object.

A non-2xx response is tried again after 1 minute, 5 minutes, and 30 minutes, then the event stops. Answer with a 2xx before doing slow work.