Skip to main content
Tribridge sends a POST to your registered endpoint whenever a payment’s status changes. Use these — not the customer’s redirect — as the source of truth for your order status.

Step 1 — Register an endpoint

Register via POST /webhooks from an authenticated dashboard session. Register separate endpoints for test and live mode — each gets its own signing secret, returned only once at creation. Your endpoint must be publicly reachable over HTTPS and respond quickly (see Step 4).

Step 2 — Know the event types

Step 3 — Parse the payload

Every webhook delivers the same JSON shape:
Example payload
Before trusting any of it, verify the signature headers (full walkthrough in Authentication):
Recompute HMAC-SHA256 over the raw body with your endpoint’s secret and compare in constant time.

Step 4 — Acknowledge correctly

  • Respond with a 2xx status within a few seconds to acknowledge delivery.
  • Tribridge retries failed deliveries with exponential backoff, up to 5 attempts. A non-2xx response (including a signature mismatch) triggers a retry — so only return 2xx after you have durably recorded the event.
  • Make your handler idempotent: the same event may be delivered more than once. Key off payment_id + event.
Your endpoint’s signing secret is returned once when you create the webhook — keep it safe and never commit it. Test and live endpoints have different secrets.

Testing webhooks end to end

  1. Register a test endpoint pointing at your server (use a tunnel like ngrok for localhost).
  2. Create a payment with your tri_test_... key and open the checkout_url.
  3. Click Simulate Payment — your test endpoint receives the full event sequence with is_test: true.
  4. Confirm your signature check passes and your order updates, then repeat with live credentials.