Skip to main content
WEBHOOK

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

X-Orb-Signature
string
required

v1= followed by the hex HMAC-SHA256 of v1:{X-Orb-Timestamp}:{raw request body}, keyed by the endpoint's webhook secret. The header may carry several space-separated signatures during a secret rotation; a receiver accepts the delivery when any v1 signature matches. Compare in constant time, and sign the bytes as received rather than a re-serialized body.

X-Orb-Timestamp
string<date-time>
required

When the delivery was signed, ISO 8601 to milliseconds. It is part of the signed message, so a receiver must reject timestamps outside its tolerance to stop replays.

Body

application/json

Issued when a payment method is created.

id
string
required

The ID of this webhook event.

created_at
string<date-time>
required

The time at which this event was created, to the second.

type
enum<string>
required

The event this payload describes.

Available options:
payment_method.created
payment_method
PaymentMethod · object
required

A payment method represents a customer's stored payment instrument held with an external payment provider (such as Adyen or Stripe).

The serialization is intentionally minimal for now; provider-pulled details (e.g. card display metadata) will be added over time.

properties
EmptyWebhookEventProperties · object
required

Response

2XX

Any 2xx acknowledges receipt.