v13

latestOpenAPI 3.1.0Proprietaryraw.githubusercontent.com2026-03-243075159.3 KB
Webhooks

Test webhook for integration verification

Webhook that is sent once to verify your webhook endpoint is correctly set up. This is sent when you configure or update your platform settings with a webhook URL.

Authentication

The webhook includes a signature in the X-UMAaas-Signature header that allows you to verify that the webhook was sent by UMAaas. To verify the signature:

  1. Get the UMAaas public key provided to you during integration
  2. Decode the base64 signature from the header
  3. Create a SHA-256 hash of the request body
  4. Verify the signature using the public key and the hash

If the signature verification succeeds, the webhook is authentic. If not, it should be rejected.

This webhook is purely for testing your endpoint integration and signature verification.

postWebhooktest-webhook

Payload

timestampstring date-time required

ISO8601 timestamp when the webhook was sent (can be used to prevent replay attacks)

webhookIdstring required

Unique identifier for this webhook delivery (can be used for idempotency)

type'INCOMING_PAYMENT' | 'OUTGOING_PAYMENT' | 'TEST' | 'BULK_UPLOAD' | 'INVITATION_CLAIMED' required

Type of webhook event, used by the receiver to identify which webhook is being received

Example payload

{
  "timestamp": "2023-08-15T14:32:00Z",
  "webhookId": "Webhook:019542f5-b3e7-1d02-0000-000000000007"
}

Response

Webhook received successfully. This confirms your webhook endpoint is properly configured.