Paymentmethodcreatedwebhookeventmessage
Issued when a payment method is created.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
v1= followed by the hex HMAC-SHA256 of v1:{X-Orb-Timestamp}:{raw request body}, keyed by the endpoint's webhook secret. The header may carry several space-separated signatures during a secret rotation; a receiver accepts the delivery when any v1 signature matches. Compare in constant time, and sign the bytes as received rather than a re-serialized body.
When the delivery was signed, ISO 8601 to milliseconds. It is part of the signed message, so a receiver must reject timestamps outside its tolerance to stop replays.
Body
Issued when a payment method is created.
The ID of this webhook event.
The time at which this event was created, to the second.
The event this payload describes.
payment_method.created A payment method represents a customer's stored payment instrument held with an external payment provider (such as Adyen or Stripe).
The serialization is intentionally minimal for now; provider-pulled details (e.g. card display metadata) will be added over time.
Response
Any 2xx acknowledges receipt.