Webhooks let you receive HTTP callbacks when events occur in your partner account - such as card transactions, KYC status changes, or balance updates.
Get current config
Response:
Update config
Event types
Verifying webhook signatures
Every webhook request includes an HMAC-SHA256 signature in the X-Contro-Signature header. The signature format is t={timestamp},v1={hmac}, where the HMAC is computed over {timestamp}.{body}.
Always verify webhook signatures before processing events. Unverified webhooks could be spoofed by attackers.
Retry policy
Failed deliveries (non-2xx responses or timeouts) are retried with exponential backoff:
After 5 failed retries, the event is marked as failed. You can manually retry failed events.
List webhook events
View the delivery history for your webhooks:
Query parameters
Event fields
Get a webhook event
Fetch a single delivery event including the full payload and the last response body. Both fields are redacted server-side to mask secrets, tokens, and other sensitive values.
Additional response fields
In addition to the list fields above, the detail response includes:
Retry a failed event
Manually retry delivery of a failed event: