Webhooks & Events

Receive updates you can verify.

Outgoing subscriptions deliver scoped events to an approved HTTPS endpoint.

Verify the raw body

Check x-trippay-signature before parsing or processing the message. Apply a timestamp tolerance and compare signatures safely.

Expect repeated delivery

Deduplicate by x-trippay-event-id. Persist the event before acknowledging it and make downstream actions idempotent.

Handle order and failure

Delivery order is not guaranteed. Re-read authoritative state when needed, and inspect failed deliveries before replaying.

Use a separately configured test environment. Production access requires technical review and provider approval where applicable.

Back to developer guides