Quick setup
Register your URL
Call
POST /org/api/v1/organizations/api-webhooks with webhook_url. It must be public HTTPS. One URL receives every event type.Verify every event
Check
X-TIMESTAMP and X-SIGNATURE before you read the body. See Signature validation.Acknowledge fast
Return
2xx within a few seconds, and do the work asynchronously. Zapyd treats any other response as a failed delivery.Deduplicate
The same event can arrive more than once. Store
id + event, and skip events you’ve already processed.Event envelope
Every event has the same shape:
Webhooks tell you that something changed. For the full object, fetch it by
id.
Signature validation
Every request includes two headers:X-TIMESTAMP— Unix timestamp when the webhook was generatedX-SIGNATURE— HMAC-SHA256 of the request, Base64 encoded
Base64(HMAC-SHA256(secret, apiKey + "|" + X-TIMESTAMP + "|" + canonicalBody)). See Authentication for the canonical body rules.
- Python
- Node.js
Event catalog
Customer events
Fired when a customer’s KYC status changes.
Metadata:
failure_reason— present onFAILED. Values:DOCUMENT_VERIFICATION_FAILED,TAX_VERIFICATION_FAILED,ADDITIONAL_INFO_VERIFICATION_FAILED,KYC_FAILED
Bank events
Fired when a bank account or UPI ID verification resolves.
Metadata:
failure_reason— present onFAILED. Values:ACCOUNT_TYPE_NRE,PENNY_DROP_FAILED,NAME_MISMATCH,BANK_RISK_CHECK_FAILED
Payin events
Fired when a payin order changes state.
Metadata:
transaction_reference_id— present onSUCCESS. The bank reference (UTR for INR) of the customer’s paymenttransaction_hash— present onSUCCESS. The on-chain transaction that delivered the cryptofailure_reason— present onFAILED. Values:INCORRECT_UTR,PAYMENT_NOT_RECEIVED, and others. See Failure Reason Referencerefund_reason— present onREFUND_INITIATEDandREFUNDED. Values:INCORRECT_AMOUNT,PAYMENT_FROM_NON_WHITELISTED_ACCOUNT,THIRD_PARTY_PAYMENT
Payout events
Fired when a payout order changes state.
Metadata:
client_reference_id— present on every payout event. Your reference from Create Payout, ornullutr— present onSUCCESS. The bank’s transfer reference (the UTR in India), usable for reconciliationfailure_reason— present onFAILED. Always the genericPayout failed; the detailed reason is not exposedrefund_reason— present onREFUNDEDreason— present onIN_REVIEW. EitherRequest for information(with anrfi_linkthe customer must complete) orUnder compliance review
PROCESSING is not sent as a webhook. Poll Fetch Payout if you need it.