Skip to main content

Webhooks

Base path: /v1/webhook-endpoints. Requires authentication.

MethodPathDescription
POST/v1/webhook-endpointsRegister an endpoint; returns the signing secret once.
GET/v1/webhook-endpointsList your endpoints.
PATCH/v1/webhook-endpoints/:idUpdate URL, subscriptions, or enabled state.
POST/v1/webhook-endpoints/:id/rotate-secretIssue a new signing secret.
DELETE/v1/webhook-endpoints/:idDelete an endpoint (204).
GET/v1/webhook-endpoints/deliveries/logInspect delivery attempts, including dead-lettered.
POST/v1/webhook-endpoints/deliveries/:deliveryId/replayRe-queue a failed or dead delivery.

Event types​

Subscribe to the events you need:

EventWhen it fires
deposit.detectedTransfer seen on-chain, below confirmation depth.
deposit.confirmedDeposit confirmed; funds credited to your balance.
deposit.orphanedDeposit rolled back by a chain reorg.
deposit.sweptDeposit consolidated internally after credit.
withdrawal.confirmedPayout confirmed on-chain.
withdrawal.failedPayout failed; reserved balance released.
address.createdNew deposit address issued.

Signature verification​

Verify each delivery by recomputing:

HMAC-SHA256(secret, "<x-cryptoreq-timestamp>.<raw body>")

Compare the result to the x-cryptoreq-signature header. Reject timestamps far from the current time to prevent replay.

Delivery status​

Deliveries move through PENDING → DELIVERED, or FAILED, or DEAD when retries are exhausted. Failed and dead deliveries can be replayed via the API.