Skip to content

Webhooks

Webhooks let your server react to events in CreditCore: a new customer, a successful or failed charge, a refund, a cancellation.

Event Sent when
CONVERSION A checkout completes and a customer is created.
TRANSACTION A charge is attempted: first payment, capture or renewal, whether it succeeded or failed.
REFUND A transaction is refunded.
CANCELLATION A customer is unsubscribed.
  1. Expose an HTTPS endpoint on your server that accepts POST requests with a JSON body.

  2. Register the URL and the events you want to receive in the platform, under Management → Webhook Config (see Webhooks in the platform). Each account has one webhook endpoint.

  3. Return a 2xx status as fast as possible. Do any heavy processing asynchronously.

Property Value
Method POST
Headers Content-Type: application/json
Timeout 5 s to connect, 10 s to respond
Success Any 2xx status
Retries None. Failed deliveries are not retried.
Order Not guaranteed. TRANSACTION and CONVERSION for the same checkout may arrive in any order.

Webhooks are not signed. Before granting access or moving money based on a webhook, confirm it with an authenticated API call:

Also restrict your endpoint to HTTPS and use a long, unguessable path.

import express from 'express';
const app = express();
app.use(express.json());
const api = (path) =>
fetch(`https://api.creditcore.io${path}`, {
headers: { Authorization: `Bearer ${process.env.CREDITCORE_API_TOKEN}` },
}).then((r) => r.json());
app.post('/webhooks/creditcore/transaction', async (req, res) => {
res.sendStatus(200); // acknowledge immediately
const event = req.body;
const tx = await api(`/api/transaction/${event.transaction_id}`); // verify
if (tx.success) {
await grantAccess(event.customer_id, event.product_id);
} else {
await notifyPaymentFailed(event.email, event.attempts);
}
});
app.listen(3000);

The same event may occasionally be delivered more than once. Deduplicate with:

  • TRANSACTION / REFUND: transaction_id
  • CONVERSION: customer_id + subscription_timestamp
  • CANCELLATION: customer_id + unsubscription_timestamp