POST/webhooks/outbound/payment.mandate.created

payment.mandate.created

This operation documents an outbound webhook request that CryptoCard Platform sends to your configured webhook URL. Sent after a payment mandate is created. Configure the destination URL and webhook secret on the company configuration. We send an HTTP `POST` with `Content-Type: application/json` and `X-Hoppacard-Signature`. The signature is a lowercase hex HMAC-SHA256 digest of the exact request body, using your webhook secret as the key. Return any 2xx status code to acknowledge the webhook. Delivery is retried for network errors, timeouts, HTTP 408, HTTP 429, and HTTP 5xx responses. The initial request may be followed by up to 15 retries over approximately 76 hours. Other HTTP 4xx responses are treated as permanent failures. Consumers must process webhook identifiers idempotently because duplicate delivery is possible.

Authentication

Send your API key in the x-api-key header on every request.

Parameters

Request parameters
FieldTypeRequiredDescription
X-Hoppacard-Signature (header)stringYesLowercase hex HMAC-SHA256 signature of the raw request body, generated with your webhook secret.
X-Hoppacard-Webhook-Id (header)stringYesStable identifier shared by every delivery attempt for this webhook. Use it as an idempotency key.
X-Hoppacard-Delivery-Attempt (header)integerYesOne-based delivery attempt number. The initial request is 1 and the final retry is 16.

Request body

application/json

Request body fields
FieldTypeRequiredDescription
idstringYesUnique webhook event id.
typepayment.mandate.createdYesWebhook event type.
domainpaymentYesBusiness domain for the event.
providerhoppacardYesProvider that originated the event.
timestampstring (date-time)YesUTC time when the webhook was created.
dataobjectYesEvent-specific payload for `payment.mandate.created`.

Responses

200 — Return any 2xx response to acknowledge receipt.

Example request

curl -X POST "https://{base_url}/webhooks/outbound/payment.mandate.created" \
  -H "x-api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"id":"…","type":"…","domain":"…","provider":"…"}'

This page is generated from the live OpenAPI specification and always matches the current API.