QashX Pay Webhooks

Signed, provider-agnostic payment lifecycle events for external developers.

QashX Pay delivers HTTPS POST requests when a payment changes state. Payloads contain canonical QashX Pay fields, not provider-specific names.

Events

EventMeaning
payment.createdA payment was created but not yet processed.
payment.awaiting_paymentThe payer has not authorized the payment yet.
payment.processingThe payment is accepted and capture is in flight.
payment.completedFunds are captured.
payment.failedThe payment terminally failed.
payment.refundedThe full or last remaining amount was refunded.
payment.cancelledThe payment was cancelled before capture.
payment.expiredAn awaiting-payment intent aged out.
payment.disputedThe payer opened a chargeback or dispute.

Signature verification

Every delivery includes these headers:

X-Qashx-Signature: <hex hmac>
X-Qashx-Timestamp: <unix ms>

Compute the expected signature with your endpoint signing secret:

const signed = `${timestamp}.${rawBody}`;
const expected = crypto
  .createHmac("sha256", secret)
  .update(signed)
  .digest("hex");

Delivery and retries

Deliveries are retried with exponential backoff. Endpoints that fail persistently are marked abandoned and can be replayed manually.

POST /functions/v1/api-v1-webhooks/{endpoint_id}/deliveries/{delivery_id}/replay

Local testing

Point a local server at your machine with a tunnel such as ngrok, register a test endpoint, then advance sandbox payments to receive correctly signed webhook deliveries.