How it works
OrendaPOSTs a signed JSON payload to a consumer URL you register for your program.
To get started,
contact the team to register your endpoint and receive
your signing secret.
Your program registers two consumer URLs — one for production and one for sandbox —
and they must be unique. Each event is delivered to the matching endpoint based on the
environment it originated in.
Common envelope
Every webhook delivery has the same top-level fields. The event type determines which additional object is included — for example, account events include anaccount object,
card events include a card object, and so on.
Events
Each event has its own reference page with the exact payload it carries.Payloads are thin by design. Transaction events carry only an identifier (e.g.
transactionId), not the full record — fetch the details through the API with your
operator credentials. Don’t expect the full objects older docs may have shown.Verifying the signature
The signing method below applies to notification webhooks only.
Card authorisation requests sign
<timestamp>.<body> instead of the body alone, so you will need a separate
verification path for those.Orenda-Payload-Signature header as a plain hex digest:
Delivery behaviour
Respond with any2xx to acknowledge. There is no automatic retry on failure — a
delivery that fails (non-2xx, timeout, or connection error) is logged and dropped, not
re-queued. Design your handler to be reliable and idempotent (de-duplicate on eventId),
and reconcile via the API (e.g. search) if you suspect missed events. For
delivery investigations, contact the team.