1. Callback Notification
English
  • Chinese
  • English
  • Open API Documentation
  • Payin
    • Payin Order - General
    • Payin Order - India
    • Payin Order - Philippines
    • Payin Order - Indonesia
    • Payin Order - Vietnam
    • Payin Order - Cryptocurrency
    • Payin Order - China
    • Payin Order - Malaysia
    • Payin Order - Pakistan
    • Payin Order - Thailand
  • Payout
    • Payout Order - General
    • Payout Order - India
    • Payout Order - Philippines
    • Payout Order - Indonesia
    • Payout Order - Vietnam
    • Payout Order - Cryptocurrency
    • Payout Order - Malaysia
    • Payout Order - Pakistan
    • Payout Order - Thailand
  • Callback Notification
    • Callback Description
    • Collection Callback
    • Payout Callback
  • Query API
    • Collection Order Query
    • Payout Order Query
    • Wallet Query
  • Examples of encryption and signature
    • Go Language Encryption and Signature Example
    • Python Encryption and Signature Example
    • PHP encryption and signature example
    • Node.js encryption and signature example
    • Environment variables and request body JSON example
    • Java encryption and signature example
  • Other instructions
    • Response Status Description
    • Order Status Description
    • Payment Method List
    • Bank Code List
    • Checkout iframe Copy Function Support Description
    • Backend Login Instructions
  1. Callback Notification

Callback Description

Webhook Asynchronous Notification#

Brief Description
Receives order status change callback notifications sent by the payment platform.
When the order status changes (such as payment success, payment failure, etc.), the platform will actively call the order callback interface to notify the merchant.

Signature Verification#

Webhook notifications must verify the signature to ensure authenticity. The verification principle is the same as request signature verification: use the platform App Secret to sign the raw payload, generate a sign, and compare it with the sign in the callback request header for validation.
Since callback fields may be extended, it is recommended to convert JSON into a Map, and then use the data in the Map for signature verification. Avoid directly converting JSON into a class object and then using the object for signature validation.

Webhook Request Headers#

Header NameDescriptionExample
X-App-IdMerchant application IDapp_platform_123
X-TsUnix timestamp (milliseconds, 13 digits)1699132800000
X-NonceRandom string (anti-replay)abcd1234efgh
X-SignHMAC-SHA256 signature value (Base64 encoded)a1b2c3d4e5f6...

Retry Mechanism#

The platform will retry Webhook notifications according to the following strategy:
Retry CountDelay TimeDescription
1ImmediateFirst attempt
25 secondsFirst retry
330 secondsSecond retry
42 minutesThird retry
510 minutesFourth retry
61 hourFifth retry
76 hoursSixth retry
816 hoursSeventh retry
Important:
Merchants must return HTTP 200 status code within 5 seconds
If the merchant returns a non-200 status code or times out, the platform will trigger retries
Maximum 8 retries, total duration approximately 17 hours
Merchants should ensure webhook interface idempotency (via event_id)

Response Parameter Description#

Callback received successfully.
The merchant should return HTTP status code 200, and the response body should return the following string.
SUCCESS
Callback received and processing failed.
The merchant should return HTTP status code 200, and the response body should return the following string.
FAILED
Modified at 2026-05-29 13:38:10
Previous
Payout Order - Thailand
Next
Collection Callback
Built with