Subscribe to webhooks
Each payment reaches you as it happens, and you act on it rather than storing it.
Your answers so far
Choose one
What to build
Write a receiver, register it as a destination, and subscribe to the events you act on. Nothing here needs a reconciliation sweep, because you aren't keeping a record whose completeness anyone will later depend on. If that changes, and it usually does, come back to this guide: the answer moves to the sweep rather than away from webhooks.
What this means for PCI
This is guidance rather than a compliance determination. Which questionnaire you are eligible for depends on your full environment, so confirm it with your QSA or your acquirer before you rely on it.
Worth knowing
- Delivery is at least once. Record the event id you have already handled and ignore a repeat, because a retry after a slow acknowledgement is an ordinary event rather than a fault.
- Acknowledge within five seconds. Put the raw body on a queue and process it after you have answered, because slow handling is retried and a retry is a duplicate you then have to discard.
- Verify the signature on every delivery, and reject anything that fails. Your endpoint is on the public internet and the signature is what makes an event yours.
- Watch the delivery log while you are building. It tells you whether a delivery you never saw was refused by your endpoint or never sent.