Skip to main content
WEBHOOK

Headers

X-Lite-Signature
string
required

Hex-encoded HMAC-SHA256 of the data object, serialized as compact JSON (no whitespace) with its fields in the order they are sent, keyed with the webhook's signing secret from the dashboard. Recompute it and compare in constant time before trusting the request.

Example:

"5f2b1c9a0d8e4f6a7b3c2d1e0f9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a"

X-Timestamp
string<date-time>
required

Time the delivery attempt was sent (ISO 8601)

Example:

"2026-09-29T10:05:01.000Z"

X-Idempotency-Key
string
required

Stays the same across retries of the same event. Use it, or data.id with event, to ignore duplicate deliveries.

Example:

"3f1c2b7a-9d4e-4c8b-a6f1-2e5d7c9b0a13"

X-Webhook-Version
string
required

Webhook payload version

Example:

"1"

Body

application/json

Body of a payout webhook request

event
enum<string>
required

Event type

Available options:
payout.succeeded,
payout.failed
Example:

"payout.succeeded"

data
object
required

Payout status carried by a payout webhook. Fetch the full payout with GET /settlements/payouts/{id}.

mode
enum<string>
required

Mode of the API key that created the payout

Available options:
live,
sandbox
Example:

"live"

Response

200

Return any 2xx status to acknowledge the event. Any other status, or no response, is treated as a failed delivery and retried with backoff.