Webhook overview
Webhooks notify your backend when a payment or withdrawal changes without requiring constant polling. Treat them as prompts to reconcile your own record with SkyPay, not as browser notifications.
Register an endpoint
- Open Settings → Webhooks in the merchant dashboard.
- Select Sandbox or Live.
- Enter the HTTPS URL that receives events. Sandbox also permits HTTP for local testing.
- Select the events you need. An empty selection subscribes to every supported event.
- Save the signing secret immediately; it is shown once.
- Send a test event and inspect the delivery log.
Each endpoint receives events only from its configured environment. A Sandbox event is never delivered to a Live endpoint.
This merchant-facing endpoint is separate from SkyPay's inbound provider routes. Paystack and Payaza send Sandbox and Live events to different SkyPay URLs, and SkyPay verifies them with environment-specific secrets before updating a payment. Your integration receives only the normalized SkyPay event.
Handler responsibilities
- Preserve the raw request bytes.
- Verify
X-SkyPay-Signaturebefore parsing or trusting the body. - Deduplicate using
X-SkyPay-Deliveryor your stored event reference. - Persist the accepted event and return a 2xx response quickly.
- Process slow business actions asynchronously.
- Retrieve the latest payment status before irreversible fulfilment.
SkyPay retries non-2xx responses and connection failures up to five attempts. See retry behavior and signature verification.