Skip to main content
If a webhookUrl was supplied at initiation, SeerBit sends a webhook event for the transaction — a transaction.completed event when the transaction is successful, and a transaction.failed event when it fails on the POS.
Before you integrate: Your webhook endpoint must be publicly accessible and able to receive POST requests from the SeerBit API.

Notifications

Delivery headers

Payload samples

Note: Fields such as responseCode and response reflect the decline reason where the terminal or card scheme provides one. amountPaid, cardNumber, and paymentType are generally absent on a failed attempt.

Payload fields

Decrypting encrypted webhooks

If your SeerBit account team has enabled payload encryption for your business, webhook payloads are encrypted with AES-256-GCM before delivery and X-Webhook-Encrypted is set to true. Follow the steps below to decrypt them on your end.
Steps to decrypt
  1. Base64-decode the webhook payload body.
  2. Take the first 12 bytes as the IV (initialization vector).
  3. Take the last 16 bytes as the GCM authentication tag.
  4. Derive the AES key as SHA-256(secretKey).
  5. Decrypt the remaining bytes (the ciphertext) using AES-256-GCM with the derived key, IV, and tag.