Webhooks
Base path: /v1/webhook-endpoints. Requires authentication.
| Method | Path | Description |
|---|---|---|
POST | /v1/webhook-endpoints | Register an endpoint; returns the signing secret once. |
GET | /v1/webhook-endpoints | List your endpoints. |
PATCH | /v1/webhook-endpoints/:id | Update URL, subscriptions, or enabled state. |
POST | /v1/webhook-endpoints/:id/rotate-secret | Issue a new signing secret. |
DELETE | /v1/webhook-endpoints/:id | Delete an endpoint (204). |
GET | /v1/webhook-endpoints/deliveries/log | Inspect delivery attempts, including dead-lettered. |
POST | /v1/webhook-endpoints/deliveries/:deliveryId/replay | Re-queue a failed or dead delivery. |
Event types
Subscribe to the events you need:
| Event | When it fires |
|---|---|
deposit.detected | Transfer seen on-chain, below confirmation depth. |
deposit.confirmed | Deposit confirmed; funds credited to your balance. |
deposit.orphaned | Deposit rolled back by a chain reorg. |
deposit.swept | Deposit consolidated internally after credit. |
withdrawal.confirmed | Payout confirmed on-chain. |
withdrawal.failed | Payout failed; reserved balance released. |
address.created | New deposit address issued. |
Signature verification
Verify each delivery by recomputing:
HMAC-SHA256(secret, "<x-cryptoreq-timestamp>.<raw body>")
Compare the result to the x-cryptoreq-signature header. Reject timestamps far from the current time to prevent replay.
Delivery status
Deliveries move through PENDING → DELIVERED, or FAILED, or DEAD when retries are exhausted. Failed and dead deliveries can be replayed via the API.