Skip to main content
Cresora Commerce
Webhooks

Webhooks

Receive real-time event notifications for payment lifecycle changes.

Webhooks are the authoritative source for payment lifecycle state on the Cresora platform. Build your integration around webhook events rather than polling the API.

How Cresora delivers webhooks

  1. You register an HTTPS endpoint URL in the Partner Portal
  2. Cresora delivers a signed POST request for each event
  3. Your server verifies the HMAC-SHA256 signature
  4. Your server returns 2xx within 10 seconds
  5. Cresora retries most non-2xx responses on a fixed ladder

Retry schedule

AttemptDelay
1st retry30 seconds
2nd retry5 minutes
3rd retry30 minutes
Window4 attempts, roughly 35 minutes total

After the 3rd retry the delivery is recorded EXHAUSTED and Cresora stops. No notification is sent — recovery is on you, via the delivery log or reconciliation. See Retry handling and Failed deliveries.

⚠Warning

The retry window is minutes, not days. Plan for reconciliation: an outage or deploy longer than ~35 minutes drops events permanently, and nothing tells you it happened.

⚠Warning

Reject deliveries with a timestamp older than 5 minutes — this protects against replay attacks. Check the X-Cresora-Timestamp header.

Webhook delivery stats

Cresora tracks delivery success rate per endpoint, and suspends an endpoint that fails at least 50 attempts with a failure rate above 90% over 24 hours. You are not alerted when this happens — no event and no email is sent, and resuming the endpoint is manual. See Failed deliveries.

Topics in this section