Overview
Webhooks allow Payviox to send real-time notifications to your server when payment events occur. When a payment is processed, Payviox sends an HTTP POST request to your configured webhook URL with the payment details.Webhooks are essential for keeping your application synchronized with payment statuses. Configure your webhook URL in the Payviox Dashboard under Settings > Webhooks.
Webhook Configuration
Setting Up Your Webhook URL
1
Configure Your Endpoint
Create an endpoint on your server to receive POST requests (e.g.,
https://yourdomain.com/api/webhook)2
Add URL to Dashboard
Go to your Payviox Dashboard and navigate to Settings > Webhooks
3
Enter Your Webhook URL
Paste your endpoint URL in the webhook URL field
4
Save Your Webhook Token
Copy your webhook token - you’ll need it to verify webhook signatures
5
Select Webhook Events
Choose which events you want to receive. By default, only
succeeded is enabled.Available Events
You can subscribe to the following webhook events:Webhook Payload Structure
Payviox sends webhooks with the following structure:Payload Fields
integer
required
The payment amount in the smallest currency unit (e.g., cents for USD)
string
required
Three-letter ISO currency code (e.g., USD, EUR, GBP)
integer
Total fees amount in the smallest currency unit (e.g., cents for USD). The customer pays
amount + fees = total. This field is present when fees have been calculated for the transaction.object
required
Custom metadata associated with the payment session
string
required
The payment event type. Possible values:
succeeded: Payment completed successfully. You can fulfill the order.pending_review: Payment flagged for fraud review. Do NOT ship until you receivesucceededordeclined.declined: Payment declined by fraud prevention. Customer has been automatically refunded.refunded: A refund has been processed for this transaction.expired: Payment session expired without completion.incomplete: A crypto payment came in short (less than the requested amount). Opt-in event. Includesamount_remaining(how much is still due). Do NOT fulfill until you receivesucceeded.
string
required
The payment provider used (e.g., stripe, paypal, crypto)
string
required
Your unique order identifier
array
required
Array of items purchased
string
Specific payment method used (e.g., card, bank_transfer)
object
Optional. Customer information if available from the payment provider.
This field is only present when customer data was collected during payment.
integer
Only present on
incomplete events. The amount still due, in the smallest currency unit (e.g., cents for USD) — how much more the customer must send to complete the payment. The amount already received equals amount - amount_remaining.Event Types
Payviox sends different webhook events based on the payment lifecycle. Here’s what each event means and how to handle it:succeeded - Payment Successful
✅ Payment Successful
The payment has been validated by the payment processor. You can safely fulfill the order.Typical flow:
- Customer completes payment
- Payment processor confirms the charge
- You receive
succeededwebhook - Ship the order / provide the service
pending_review - Fraud Review Required
⚠️ Pending Review
The payment has been flagged by our fraud detection system for manual review. Do NOT ship until you receive a final decision.Typical flow:
- Customer completes payment
- Fraud detection flags the transaction
- You receive
pending_reviewwebhook - Admin reviews the transaction
- You receive either
succeededordeclinedwebhook
declined - Fraud Declined
❌ Declined (Fraud)
The payment was automatically declined by the fraud prevention system. The customer has been automatically refunded.Typical flow:
- Customer completes payment
- Fraud score exceeds threshold
- Automatic refund is issued
- You receive
declinedwebhook - Do NOT ship the order
refunded - Payment Refunded
↩️ Refunded
A refund has been processed for this transaction.Typical flow:
- Original payment was successful
- Refund is requested (by you or the customer)
- Refund is processed
- You receive
refundedwebhook
expired - Session Expired
⏰ Expired
The payment session expired before the customer completed payment.Typical flow:
- Payment session is created
- Customer does not complete payment within the session lifetime
- Session expires automatically
- You receive
expiredwebhook
incomplete - Crypto Payment Underpaid
⚠️ Incomplete
A crypto payment came in short — the customer sent less than the requested amount. This is an opt-in event (enable it in your webhook settings), and only applies to crypto payments.The payload includes
amount_remaining (how much is still due, in the smallest currency unit). The amount already received equals amount - amount_remaining.Typical flow:- Customer pays a crypto invoice but sends less than the requested amount
- You receive
incomplete(withamount_remaining) - Customer sends the remaining amount to the same address
- You receive
succeeded
succeeded.Webhook Headers
Every webhook request includes these headers:Signature Verification
TheSignature header contains an HMAC SHA256 hash of the request body, signed with your webhook token. Here’s how to verify it:
Verification Algorithm
- Get the raw request body (JSON string)
- Compute HMAC SHA256 hash using your webhook token as the secret key
- Compare the computed signature with the
Signatureheader - Only process the webhook if signatures match
Implementation Examples
Retry Logic
Payviox implements an automatic retry mechanism for failed webhook deliveries:1
First Attempt
Instant delivery (0 seconds)
2
Second Attempt
30 seconds after first failure
3
Third Attempt
5 minutes after second failure
4
Fourth Attempt
30 minutes after third failure
After 4 failed attempts, the webhook will be marked as failed. You can manually retry failed webhooks from the Payviox Dashboard.
Success Criteria
A webhook is considered successfully delivered when your endpoint:- Returns HTTP status code
200 - Responds within 30 seconds
Troubleshooting
Common Issues
Signature Verification Failing
Signature Verification Failing
Possible causes:
- Using the wrong webhook token
- Parsing/modifying the request body before verification
- Incorrect HMAC algorithm (must be SHA256)
Webhooks Not Being Received
Webhooks Not Being Received
Possible causes:
- Incorrect webhook URL in dashboard
- Firewall blocking Payviox IP addresses
- Server not responding within 30 seconds
Duplicate Webhook Processing
Duplicate Webhook Processing
Possible causes:
- Not implementing idempotency checks
- Slow response times causing retries
Webhook Timeout
Webhook Timeout
Possible causes:
- Processing taking too long before responding
- Database locks or slow queries
Security Checklist
Need Help?
If you’re having trouble with webhook integration:- Check the Webhook Logs in your dashboard
- Review your server logs for errors
- Contact support@payviox.com for assistance