Webhooks you can verify, retry and replay.
Every event is signed, retried on a fixed schedule when your endpoint fails, and can be redelivered from the console. Each carries a stable event ID so you apply it once.
Events
| Event | When it's sent |
|---|---|
| payment.completed | Receipt was confirmed and matched to this payment. Credit the order. |
| payment.expired | The payment request expired before any receipt. Release the order. |
| payment.review_opened | A receipt couldn't be matched to exactly one request. Nothing to credit yet. |
Retry schedule
A delivery succeeds when your endpoint answers 2xx within 10 seconds. Otherwise it's retried:
| Attempt | After the previous attempt |
|---|---|
| 1 | Immediately |
| 2 | 1 minute |
| 3 | 5 minutes |
| 4 | 30 minutes |
| 5 | 2 hours |
| 6 | 6 hours |
| 7 | 24 hours, then marked failed and kept for redelivery |
Every attempt, visible in the console
See each delivery with your endpoint's response code and latency. Redeliver any event with the same event ID once your endpoint is back.
Webhooks
Endpoint
https://api.example.com/webhooks/marupay ActiveEventAttemptResponseLatencyTime
payment.completedevt_5hRk2Pq9Wd#1200118ms14:01:33 Redeliverpayment.completedevt_5hRj8Ld2Tx#1200142ms13:58:50 Redeliverpayment.expiredevt_5hRh1Vn6Kc#120097ms13:52:15 Redeliverpayment.completedevt_5hRg4Bs0Ym#2200164ms13:45:04 Redeliverpayment.completedevt_5hRg4Bs0Ym#15033,012ms13:44:04payment.completedevt_5hRf7Mc3Qa#1200131ms13:39:27 Redeliverpayment.completedevt_5hRd0Xw8Ne#1200126ms13:31:59 RedeliverHandling events well
Verify first
Check the HMAC-SHA256 signature over the timestamp and the raw body.
Answer fast
Return 2xx, then do slow work in the background.
Apply once
Store the event ID; a retried or redelivered event reuses it.
Don't rely on order
Events can arrive out of order. Read the payment's status if in doubt.
Try it against your endpoint.
Test accounts can send signed sample events to a staging endpoint from the console.