Octane

Webhooks overview

Octane sends a signed HTTPS POST to your endpoint when a transaction is confirmed or an external transaction is recorded. Endpoint requirements and event types.

Webhooks let Octane notify your system in near real time, instead of you polling the Pull API. Whenever one of your transactions is confirmed, or an external transaction is recorded, Octane sends an HTTPS POST to your endpoint with the full transaction record.

How do webhooks work?

  1. You give Octane an HTTPS URL when your API key is created (or later, on request). Octane generates a webhook secret and shares it with you once.
  2. When a transaction reaches CONFIRMED or EXTERNAL, Octane builds the payload and POSTs it to your URL, signed with the secret.
  3. Your endpoint verifies the signature and returns any 2xx status within 500 ms.
  4. If delivery fails, Octane retries up to 3 times. Persistent failures are logged and, after prolonged failure, the webhook is disabled and you are notified by email.

A feed of new transactions, not a lifecycle mirror

Webhooks fire once per transaction, when it becomes CONFIRMED or EXTERNAL. Later changes (a void or cancellation) are not pushed. Use the Pull API to detect them. See Best practices.

Endpoint requirements

RequirementDetail
Scheme and porthttps:// on port 443 only. Plain HTTP and non-standard ports are rejected.
ReachabilityThe hostname must resolve to a public IP address. Private, loopback, link-local and cloud-metadata ranges are rejected.
TLSA valid, publicly trusted certificate.
RedirectsNot followed. The URL must respond directly.
TimeoutRespond within 500 ms, measured from connection to complete response. Return 2xx immediately, then process the event asynchronously. A slow response counts as a failed delivery.
SuccessAny 2xx status. The response body is ignored.

One webhook URL is configured per API key. If you need several destinations, ask Octane for a key per destination.

What triggers a webhook?

EventSent when
transaction.confirmedA transaction becomes CONFIRMED, including refund transactions for duplicates, variances and resolved disputes.
transaction.externalAn EXTERNAL transaction (a station outside the Octane network) is recorded.
webhook.testOn request, to verify your endpoint.

Not sent: PENDING, VOID or CANCELED transactions, later status changes of a transaction already delivered, and manual balance adjustments.

Only transactions created after the webhook URL was set are pushed. Use the Pull API to backfill anything earlier.

Next steps

On this page