QashX Pay delivers HTTPS POST requests when a payment changes state. Payloads contain canonical QashX Pay fields, not provider-specific names.
Events
| Event | Meaning |
|---|---|
payment.created | A payment was created but not yet processed. |
payment.awaiting_payment | The payer has not authorized the payment yet. |
payment.processing | The payment is accepted and capture is in flight. |
payment.completed | Funds are captured. |
payment.failed | The payment terminally failed. |
payment.refunded | The full or last remaining amount was refunded. |
payment.cancelled | The payment was cancelled before capture. |
payment.expired | An awaiting-payment intent aged out. |
payment.disputed | The payer opened a chargeback or dispute. |
Signature verification
Every delivery includes these headers:
X-Qashx-Signature: <hex hmac>
X-Qashx-Timestamp: <unix ms>
Compute the expected signature with your endpoint signing secret:
const signed = `${timestamp}.${rawBody}`;
const expected = crypto
.createHmac("sha256", secret)
.update(signed)
.digest("hex");
- Reject requests where the signature does not match.
- Reject timestamps outside a five-minute replay window.
- Store processed event IDs so handlers remain idempotent.
Delivery and retries
Deliveries are retried with exponential backoff. Endpoints that fail persistently are marked abandoned and can be replayed manually.
POST /functions/v1/api-v1-webhooks/{endpoint_id}/deliveries/{delivery_id}/replay
Local testing
Point a local server at your machine with a tunnel such as ngrok, register a test endpoint, then advance sandbox payments to receive correctly signed webhook deliveries.