Receive and verify a webhook
Stand up a receiver, subscribe it to transaction events, and prove the delivery that arrives came from this platform.
Your answers so far
- What are you testing next?
- The events my systems receive after a payment. Change
Choose one
What to build
Run the webhooks blueprint. It registers your endpoint as a signed destination, sends a test delivery, subscribes to the transaction events, and triggers a sandbox sale, so you see a real delivery and verify its signature.
What this means for PCI
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- Delivery is at least once. Test that a repeated event id is ignored, not applied twice.
- Acknowledge within five seconds and process afterward, because a slow acknowledgement is retried.