Event catalogue
Webhook events with their payload schemas, from the contract's webhooks section. Register endpoints and verify signatures as described in Webhooks.
payment.status_changed
Integrator callback: payment.status_changed
Delivered to registered integrator endpoints. Headers: WireBloom-Event-Id, WireBloom-Event-Type, WireBloom-Timestamp (unix seconds), WireBloom-Signature: v1=<hex HMAC-SHA256(secret, timestamp + "." + rawBody)> (several v1= values during secret rotation). Reject if the timestamp is older than 5 minutes; compare in constant time; de-duplicate on WireBloom-Event-Id. Respond 2xx within 10 s; retries with exponential backoff for 72 h (1 m, 5 m, 30 m, 2 h, 6 h, then every 12 h); endpoint disabled after 72 h of failures.
Payload
idUuidrequiredtypeIntegratorEventTyperequiredcreatedAtTimestamprequiredapiVersionstringrequiredtenantIdUuidrequireddataobjectrequiredThin payload: fetch the full resource with the API (
GET /payments/{id}…) using the id.Fields of data
objectstringrequiredidUuidrequiredstatusstring | nullpreviousStatusstring | nullamountMoney | nulltestbooleantrueonPOST /integrator-webhooks/{webhookId}/testevents (also headerWireBloom-Test: true).sandboxbooleantrueon events simulated through/sandbox/*.relatedobjectcompliance_hold.*: the held payment or incoming payment.Fields of related
objectstringrequiredidUuidrequired
customerIdUuid | null
incoming_payment.received
Integrator callback: incoming_payment.received
Delivered to registered integrator endpoints. Headers: WireBloom-Event-Id, WireBloom-Event-Type, WireBloom-Timestamp (unix seconds), WireBloom-Signature: v1=<hex HMAC-SHA256(secret, timestamp + "." + rawBody)> (several v1= values during secret rotation). Reject if the timestamp is older than 5 minutes; compare in constant time; de-duplicate on WireBloom-Event-Id. Respond 2xx within 10 s; retries with exponential backoff for 72 h (1 m, 5 m, 30 m, 2 h, 6 h, then every 12 h); endpoint disabled after 72 h of failures.
Payload
idUuidrequiredtypeIntegratorEventTyperequiredcreatedAtTimestamprequiredapiVersionstringrequiredtenantIdUuidrequireddataobjectrequiredThin payload: fetch the full resource with the API (
GET /payments/{id}…) using the id.Fields of data
objectstringrequiredidUuidrequiredstatusstring | nullpreviousStatusstring | nullamountMoney | nulltestbooleantrueonPOST /integrator-webhooks/{webhookId}/testevents (also headerWireBloom-Test: true).sandboxbooleantrueon events simulated through/sandbox/*.relatedobjectcompliance_hold.*: the held payment or incoming payment.Fields of related
objectstringrequiredidUuidrequired
customerIdUuid | null
exchange.completed
Integrator callback: exchange.completed
Delivered to registered integrator endpoints. Headers: WireBloom-Event-Id, WireBloom-Event-Type, WireBloom-Timestamp (unix seconds), WireBloom-Signature: v1=<hex HMAC-SHA256(secret, timestamp + "." + rawBody)> (several v1= values during secret rotation). Reject if the timestamp is older than 5 minutes; compare in constant time; de-duplicate on WireBloom-Event-Id. Respond 2xx within 10 s; retries with exponential backoff for 72 h (1 m, 5 m, 30 m, 2 h, 6 h, then every 12 h); endpoint disabled after 72 h of failures.
Payload
idUuidrequiredtypeIntegratorEventTyperequiredcreatedAtTimestamprequiredapiVersionstringrequiredtenantIdUuidrequireddataobjectrequiredThin payload: fetch the full resource with the API (
GET /payments/{id}…) using the id.Fields of data
objectstringrequiredidUuidrequiredstatusstring | nullpreviousStatusstring | nullamountMoney | nulltestbooleantrueonPOST /integrator-webhooks/{webhookId}/testevents (also headerWireBloom-Test: true).sandboxbooleantrueon events simulated through/sandbox/*.relatedobjectcompliance_hold.*: the held payment or incoming payment.Fields of related
objectstringrequiredidUuidrequired
customerIdUuid | null
recipient.status_changed
Integrator callback: recipient.status_changed
Delivered to registered integrator endpoints. Headers: WireBloom-Event-Id, WireBloom-Event-Type, WireBloom-Timestamp (unix seconds), WireBloom-Signature: v1=<hex HMAC-SHA256(secret, timestamp + "." + rawBody)> (several v1= values during secret rotation). Reject if the timestamp is older than 5 minutes; compare in constant time; de-duplicate on WireBloom-Event-Id. Respond 2xx within 10 s; retries with exponential backoff for 72 h (1 m, 5 m, 30 m, 2 h, 6 h, then every 12 h); endpoint disabled after 72 h of failures.
Payload
idUuidrequiredtypeIntegratorEventTyperequiredcreatedAtTimestamprequiredapiVersionstringrequiredtenantIdUuidrequireddataobjectrequiredThin payload: fetch the full resource with the API (
GET /payments/{id}…) using the id.Fields of data
objectstringrequiredidUuidrequiredstatusstring | nullpreviousStatusstring | nullamountMoney | nulltestbooleantrueonPOST /integrator-webhooks/{webhookId}/testevents (also headerWireBloom-Test: true).sandboxbooleantrueon events simulated through/sandbox/*.relatedobjectcompliance_hold.*: the held payment or incoming payment.Fields of related
objectstringrequiredidUuidrequired
customerIdUuid | null
approval.requested
Integrator callback: approval.requested
Delivered to registered integrator endpoints. Headers: WireBloom-Event-Id, WireBloom-Event-Type, WireBloom-Timestamp (unix seconds), WireBloom-Signature: v1=<hex HMAC-SHA256(secret, timestamp + "." + rawBody)> (several v1= values during secret rotation). Reject if the timestamp is older than 5 minutes; compare in constant time; de-duplicate on WireBloom-Event-Id. Respond 2xx within 10 s; retries with exponential backoff for 72 h (1 m, 5 m, 30 m, 2 h, 6 h, then every 12 h); endpoint disabled after 72 h of failures.
Payload
idUuidrequiredtypeIntegratorEventTyperequiredcreatedAtTimestamprequiredapiVersionstringrequiredtenantIdUuidrequireddataobjectrequiredThin payload: fetch the full resource with the API (
GET /payments/{id}…) using the id.Fields of data
objectstringrequiredidUuidrequiredstatusstring | nullpreviousStatusstring | nullamountMoney | nulltestbooleantrueonPOST /integrator-webhooks/{webhookId}/testevents (also headerWireBloom-Test: true).sandboxbooleantrueon events simulated through/sandbox/*.relatedobjectcompliance_hold.*: the held payment or incoming payment.Fields of related
objectstringrequiredidUuidrequired
customerIdUuid | null
statement.available
Integrator callback: statement.available
Delivered to registered integrator endpoints. Headers: WireBloom-Event-Id, WireBloom-Event-Type, WireBloom-Timestamp (unix seconds), WireBloom-Signature: v1=<hex HMAC-SHA256(secret, timestamp + "." + rawBody)> (several v1= values during secret rotation). Reject if the timestamp is older than 5 minutes; compare in constant time; de-duplicate on WireBloom-Event-Id. Respond 2xx within 10 s; retries with exponential backoff for 72 h (1 m, 5 m, 30 m, 2 h, 6 h, then every 12 h); endpoint disabled after 72 h of failures.
Payload
idUuidrequiredtypeIntegratorEventTyperequiredcreatedAtTimestamprequiredapiVersionstringrequiredtenantIdUuidrequireddataobjectrequiredThin payload: fetch the full resource with the API (
GET /payments/{id}…) using the id.Fields of data
objectstringrequiredidUuidrequiredstatusstring | nullpreviousStatusstring | nullamountMoney | nulltestbooleantrueonPOST /integrator-webhooks/{webhookId}/testevents (also headerWireBloom-Test: true).sandboxbooleantrueon events simulated through/sandbox/*.relatedobjectcompliance_hold.*: the held payment or incoming payment.Fields of related
objectstringrequiredidUuidrequired
customerIdUuid | null