Skip to main content
WEBHOOK

Headers

X-Karat-Signature
string
required

HMAC-SHA256 signature of the delivery, in the format v1=<base64>.

X-Karat-Webhook-Timestamp
string
required

Unix epoch seconds when the event was sent. Used in the signed payload and for replay protection.

X-Karat-Subscription-Id
string<uuid>
required

The subscription this delivery belongs to. Use it to look up the signing secret.

X-Karat-Webhook-Id
string<uuid>
required

Unique delivery ID, for deduplication.

Body

application/json

Envelope delivered to your callback URL when an event fires.

id
string<uuid>
required

Unique ID for this delivery.

event
enum<string>
required
Available options:
transaction.pending,
transaction.updated,
transaction.posted,
transaction.pending_completed
Allowed value: "transaction.pending_completed"
Example:

"payout.updated"

created_at
string<date-time>
required
subscription_id
string<uuid>
required
data
object
required

Event-specific payload.

Response

200

Return a 2xx status to acknowledge receipt.