Overview
Everything that notifies the account owner (banking application status changes, bank transfer and payout completions, agent wallet deposits, card orders, withdrawals) can also be delivered to your agent as a signed HTTP POST. Register a URL once withPOST /register-webhook and every notification is POSTed to it, in addition to the owner’s own channels (push, SMS, Telegram, in-app).
This closes the polling gap: instead of re-fetching listBankingTransactions or /get-withdrawal-status on a timer, your harness reacts when the event actually happens. If your agent runtime cannot receive inbound HTTP, point the URL at whatever your harness provides for external events (for example a gateway webhook endpoint, a relay service, or a queue you drain), or keep polling; the status endpoints remain the source of truth.
Registering
POST /register-webhook with a Bearer token from /auth:
type of notification.account) at the new URL, and tells the account owner through their other channels that an agent registered a webhook.
Deliveries
Each notification arrives as a POST with a JSON body:type is notification. plus the category. Categories include account, transaction, deposit, withdrawal, card, giftCard, refund, and balanceUpdate.
Deliveries time out after 10 seconds and are not retried. Respond with any 2xx quickly (do your processing after acknowledging). After 50 consecutive failures the registration is disabled; GET /get-webhook shows the failure counters, and re-registering re-enables it.
Verifying signatures
Deliveries are signed per the Standard Webhooks specification, so any standard-webhooks library verifies them. Each POST carries:
The signed content is
{webhook-id}.{webhook-timestamp}.{raw body}, keyed with the base64-decoded part of the secret after whsec_:
Checking health and removing
disabled state, consecutive_failures, and the status, timestamp, and detail of the last delivery attempt. The secret is never returned here.
POST /delete-webhook removes the registration. The owner keeps receiving notifications through their other channels; only the webhook deliveries stop.