Skip to main content
Webhooks let you subscribe to Nuvion events and receive HTTP POST notifications when those events occur. Each webhook is scoped to the authenticated entity and can subscribe to specific event types or all events. See Webhooks overview for the delivery model, retries, and signature verification.

The Webhook object

string
Unique webhook identifier.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
string
The HTTPS endpoint Nuvion delivers events to. Must use the https protocol.
number
Duration in seconds until the webhook expires. After expiry, no further events are delivered and the webhook status becomes inactive.
object
The set of events this webhook is subscribed to.
string[]
Read-only. A flattened summary of the enabled events, using group.all where every event in a group is enabled. e.g. ["accounts.all", "outflows.all"].
string
System-generated signing secret. Nuvion derives an HMAC from this value to sign each delivery. Returned once, at creation or when rotated via rotate_secret: store it securely before leaving the page. It is never returned on subsequent requests. See Verifying signatures for how to validate incoming requests.
string
Optional short description to identify the webhook in the dashboard.
string[]
Optional list of tags for organizing webhooks.
string
Webhook status. One of active or inactive. Defaults to active at creation.
number
Unix timestamp in milliseconds when the webhook was created.
number
Unix timestamp in milliseconds when the webhook was last updated.
number
0 if the webhook is active. Non-zero if the webhook has been deleted.
object
Read-only delivery statistics for this webhook.
Example

Create a webhook

POST /entity-webhooks Registers a new webhook endpoint for the authenticated entity.

Request parameters

string
required
The HTTPS endpoint Nuvion posts events to. Must begin with https://. Invalid URLs or non-HTTPS URLs are rejected.
number
required
Duration in seconds until the webhook expires. After expiry, deliveries stop and the webhook status becomes inactive.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
object
required
The events to subscribe to. Set all to subscribe to every event, or enable specific events within one or more groups. See enabled_events fields for the full group structure.
boolean
When true, subscribes to every event type. Overrides all other selections in this object.

Response

Returns 201 Created with the new webhook object.
Copy and store the secret immediately after creating the webhook.

Update a webhook

PATCH /entity-webhooks/:id Updates an existing webhook. Only the fields you include are changed; omitted fields retain their current values.

Path parameters

string
required
The ID of the webhook to update.

Request parameters

string
New HTTPS delivery URL. Must begin with https://.
boolean
Whether to rotate the webhook’s signing secret. Defaults to false.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
Set rotate_secret to true if you’re rotating your secret key. The new value is returned once in the response, the same as at creation; it isn’t returned on later requests.

Response

Returns 200 OK with the updated webhook object.

Get a webhook

GET /entity-webhooks/:webhookId Retrieves a single webhook by ID.

Path parameters

string
required
The ID of the webhook to retrieve.

Query parameters

string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Response

Returns 200 OK with the webhook object.
Response

List webhooks

GET /entity-webhooks Returns a paginated list of all webhooks for the authenticated entity.

Query parameters

integer
Number of results per page. Between 1 and 100. Defaults to 20.
string
ULID pagination cursor from a previous response. Omit for the first page.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Response

Returns 200 OK with a paginated list of webhook objects.
Response

Delete a webhook

DELETE /entity-webhooks/:webhookId Permanently deletes a webhook. Nuvion stops delivering events to the endpoint immediately.

Path parameters

string
required
The ID of the webhook to delete.

Request parameters

string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Response

Returns 200 OK confirming deletion.
Response
Deletion is irreversible. All delivery history is retained in logs, but the webhook configuration and endpoint registration are permanently removed.

The Webhook Log object

Each delivery attempt is recorded as a log entry. Logs are immutable and retained regardless of delivery outcome.
string
Unique log entry identifier.
string
The ID of the entity this log belongs to.
string
The ID of the event that triggered this delivery.
string
The ID of the webhook that triggered this delivery.
string
The URL this delivery was sent to at the time of the attempt.
object
The request Nuvion sent to the webhook endpoint.
object
The response received from the webhook endpoint.
object
Timestamps for the delivery lifecycle.
number
Unix timestamp in milliseconds when the log entry was created.
number
Unix timestamp in milliseconds when the log entry was last updated.
number
0 for all log entries. Logs are immutable and never deleted.

List webhook logs

GET /webhook-logs Returns a paginated list of delivery log entries for the authenticated entity.

Query parameters

integer
Number of results per page. Between 1 and 100. Defaults to 20.
string
ULID pagination cursor from a previous response. Omit for the first page.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Response

Returns 200 OK with a paginated list of log objects.
Response
X-Nuvion-Event-Signature and the other delivery headers are recorded as sent. See Verifying signatures for how to validate them.

Send a test event

POST /webhook-tests Sends a test delivery to an existing webhook endpoint, so you can verify it’s reachable and correctly signs and receives deliveries without waiting for a real event.

Request parameters

string
required
The ID of the webhook to send the test event to.
string
required
The event group to simulate. One of entities, accounts, account_details, inflows, outflows, funding_sessions, payment_intent, payment_dispute, payment_refund, or cards.
string
required
The specific event to simulate within the group. One of created, updated, deleted, completed, failed, cancelled, refunded, frozen, or unfrozen.Not all combinations of event_group and event_name are valid. For example, funding_sessions.created does not exist. Refer to the enabled_events structure for supported combinations.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.

Response

Returns 201 Created confirming the test was dispatched.
Response
The test delivery’s body only contains event_group and event_name, not the full event/data shape a real event payload has:
Use this endpoint to confirm your webhook is reachable and that your signature verification works, not to test your handler’s parsing logic against realistic event data. See Event types for real payload shapes.
Test events appear in webhook logs the same as live events. Check the logs to inspect the full request and response if your endpoint didn’t receive the payload as expected.

What’s next

Webhooks overview

Delivery model, retries, idempotency, and signature verification.

Event types

Full payload schemas and examples for every event.