Webhooks
Receive real-time event notifications for payment lifecycle changes.
Webhooks are the authoritative source for payment lifecycle state on the Cresora platform. Build your integration around webhook events rather than polling the API.
How Cresora delivers webhooks
- You register an HTTPS endpoint URL in the Partner Portal
- Cresora delivers a signed POST request for each event
- Your server verifies the HMAC-SHA256 signature
- Your server returns
2xxwithin 10 seconds - Cresora retries most non-
2xxresponses on a fixed ladder
Retry schedule
| Attempt | Delay |
|---|---|
| 1st retry | 30 seconds |
| 2nd retry | 5 minutes |
| 3rd retry | 30 minutes |
| Window | 4 attempts, roughly 35 minutes total |
After the 3rd retry the delivery is recorded EXHAUSTED and Cresora stops. No notification is sent — recovery is on you, via the delivery log or reconciliation. See Retry handling and Failed deliveries.
The retry window is minutes, not days. Plan for reconciliation: an outage or deploy longer than ~35 minutes drops events permanently, and nothing tells you it happened.
Reject deliveries with a timestamp older than 5 minutes — this protects against replay attacks. Check the X-Cresora-Timestamp header.
Webhook delivery stats
Cresora tracks delivery success rate per endpoint, and suspends an endpoint that fails at least 50 attempts with a failure rate above 90% over 24 hours. You are not alerted when this happens — no event and no email is sent, and resuming the endpoint is manual. See Failed deliveries.