Webhooks
Configure where Depa sends webhooks, get the secret to verify them, and inspect or re-send past deliveries.
Webhooks are grouped into topics, such as fiat_payment or identification, and each
topic has its own list of URLs. See the webhooks guide for how
deliveries are signed and retried, and the event catalogue for
every event and its payload.
/users/settingsReturns the settings of your user and its vault. For webhooks, webhook_url_list shows the
URLs configured for each topic and webhook_secret is the secret that signs every delivery.
Store the secret on your server and use it to verify the Depasify-Signature header.
Authorization
ApiToken Your API key, or the JWT from POST /sign_in, as the raw header value: Authorization: <token>. Don't add a Bearer prefix.
In: header
Response Body
application/json
application/json
curl -X GET "https://example.com/users/settings" \ -H "Authorization: <token>"{ "data": { "id": "7de89d62-160b-4d12-a7b1-d3b3ac82c910", "otp_required_for_login": true, "redirect_url": null, "trading_fee": 0.005, "webhook_url_list": { "fiat_payment": [ "https://api.yourcompany.com/depa/webhooks" ], "blockchain_payment": [ "https://api.yourcompany.com/depa/webhooks" ], "identification": [ "https://api.yourcompany.com/depa/webhooks" ] }, "webhook_secret": "9kQ2vXbT7hR4mW8nZ1cF6yJ3pL5sD0aG2eU7iO4tB9xK1qV6wN8rM3zH5jC0fY2u", "secret_key_present": false }}/users/update_webhookSets the URLs that receive each topic's webhooks. Send a map of topic to a list of HTTPS URLs. Only the topics you include change; the others keep their URLs. Send an empty list to stop a topic's webhooks.
The settings belong to your vault, so they apply to every user and account in it. Card
payment events go to card_payment when it has URLs, and to fiat_payment otherwise.
Authorization
ApiToken Your API key, or the JWT from POST /sign_in, as the raw header value: Authorization: <token>. Don't add a Bearer prefix.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
curl -X PUT "https://example.com/users/update_webhook" \ -H "Authorization: <token>" \ -H "Content-Type: application/json" \ -d '{ "webhook_url": { "fiat_payment": [ "https://api.yourcompany.com/depa/webhooks" ], "blockchain_payment": [ "https://api.yourcompany.com/depa/webhooks" ], "identification": [ "https://api.yourcompany.com/depa/webhooks", "https://backup.yourcompany.com/depa/webhooks" ] } }'{ "message": "webhook_url updated succesfully"}/webhook_logsReturns the webhooks Depa has sent to your vault, newest first, with their payload, status
and the last error your server returned. Filter by topic (type) and status, and search
the payloads, for example by payment ID. Send type and status together: requests without
both currently return no results.
Authorization
ApiToken Your API key, or the JWT from POST /sign_in, as the raw header value: Authorization: <token>. Don't add a Bearer prefix.
In: header
Query Parameters
Topic of the deliveries to return, for example fiat_payment. Send it together with status: requests without both currently return no results.
Value in
- "account"
- "identification"
- "fiat_payment"
- "card_payment"
- "blockchain_payment"
- "blockchain_wallet"
- "open_banking_transaction_completed"
- "daily_settlement"
- "ticket"
- "transaction_monitoring"
- "manual_review"
Delivery status to return. Send it together with type.
Value in
- "pending"
- "processing"
- "completed"
- "partial"
- "failed"
Text to look for in the payload, such as a payment ID or an event name.
Vault whose deliveries to return. Defaults to your first vault.
uuidPage number, starting at 1.
1 <= value1Number of results per page. Defaults to 80.
1 <= valueResponse Body
application/json
application/json
curl -X GET "https://example.com/webhook_logs?type=fiat_payment&status=failed&search=7e2a9c4b-5d1f-4b8e-9a3c-6f0e2d8b1a74&vault_id=3c8e1f5a-7b2d-4e9c-a6f1-0d4b8e2c7a95&page=1&per_page=80" \ -H "Authorization: <token>"{ "data": [ { "id": "5d2c8e7a-1f4b-4a9e-b3c6-8e0d7f1a2b94", "event": "fiat_payment", "status": "completed", "fail_reason": null, "payload": { "data": { "event": "fiat_payment_received", "attributes": { "fiat_payment_uuid": "7e2a9c4b-5d1f-4b8e-9a3c-6f0e2d8b1a74", "amount": "1250.0", "currency": "EUR", "status": "confirmed" } } }, "retries": 1, "urls_destiny": [ "https://api.yourcompany.com/depa/webhooks" ], "created_at": 1772813114 } ], "pagination": { "current_page": 1, "per_page": 80, "total_pages": 1, "total_count": 2 }}/webhook_logs/{webhook_log_id}/retrySends a past delivery again, with the same payload, to the URLs currently configured for its topic. Use it after fixing your endpoint, once Depa's automatic retries have run out.
Authorization
ApiToken Your API key, or the JWT from POST /sign_in, as the raw header value: Authorization: <token>. Don't add a Bearer prefix.
In: header
Path Parameters
ID of the delivery to send again.
uuidResponse Body
application/json
application/json
application/json
curl -X POST "https://example.com/webhook_logs/5d2c8e7a-1f4b-4a9e-b3c6-8e0d7f1a2b94/retry" \ -H "Authorization: <token>"{ "data": { "id": "5d2c8e7a-1f4b-4a9e-b3c6-8e0d7f1a2b94", "event": "fiat_payment", "status": "completed", "fail_reason": null, "payload": { "data": { "event": "fiat_payment_received", "attributes": { "fiat_payment_uuid": "7e2a9c4b-5d1f-4b8e-9a3c-6f0e2d8b1a74", "amount": "1250.0", "currency": "EUR", "status": "confirmed" } } }, "retries": 1, "urls_destiny": [ "https://api.yourcompany.com/depa/webhooks" ], "created_at": 1772813114 }}Authentication
Authenticate every request by sending a token as the raw value of the `Authorization` header, without a `Bearer` prefix.
Accounts
An account owns balances, bank accounts, blockchain wallets and ledger entries. Each account belongs to a vault and is linked to the identification of its holder.