webhookUrl was supplied at initiation, SeerBit sends a webhook event for the transaction — a transaction.completed event when the transaction is successful, and a transaction.failed event when it fails on the POS.
Before you integrate: Your webhook endpoint must be publicly accessible and able to receive POST requests from the SeerBit API.
Notifications
Delivery headers
Payload samples
Note: Fields such asresponseCodeandresponsereflect the decline reason where the terminal or card scheme provides one.amountPaid,cardNumber, andpaymentTypeare generally absent on a failed attempt.
Payload fields
Decrypting encrypted webhooks
If your SeerBit account team has enabled payload encryption for your business, webhook payloads are encrypted with AES-256-GCM before delivery andX-Webhook-Encrypted is set to true. Follow the steps below to decrypt them on your end.
Steps to decrypt
- Base64-decode the webhook payload body.
- Take the first 12 bytes as the IV (initialization vector).
- Take the last 16 bytes as the GCM authentication tag.
- Derive the AES key as
SHA-256(secretKey). - Decrypt the remaining bytes (the ciphertext) using AES-256-GCM with the derived key, IV, and tag.