How Webhooks Work
- An event occurs (e.g., a customer completes a payment)
- Kyren Pay sends an HTTP POST request to your configured webhook URL
- The request includes a signature for verification
- Your server verifies the signature, persists the event, and returns
200within 10 seconds - Your worker processes the persisted event with idempotency and its own retries
Configuring Webhooks
Set up your webhook endpoint in the Merchant Dashboard:- Go to Dashboard > Developer > Webhook Settings
- Enter your Webhook URL (e.g.,
https://yoursite.com/webhooks/kyren) - Copy your Webhook Secret — you’ll need this to verify signatures
Webhook Payload
Every webhook request includes these headers:
The request body is a JSON object:
Best Practices
Verify Signatures
Always verify the
X-Kyren-Signature header to ensure the webhook is authentic. See Webhook Signatures.Return 200 Quickly
Verify the signature and durably store the event before returning
200. Return non-2xx if persistence fails, so Kyren can retry.Handle Duplicates
Use the event
id to deduplicate. Your endpoint may receive the same event more than once due to retries.Use a Queue
For asynchronous processing, persist to a durable inbox or queue and acknowledge only after storage succeeds. Workers need their own retries after Kyren receives
2xx.Next Steps
Events
See all event types
Signatures
Verify webhook signatures
Retries
Understand retry behavior