The Webhook object
string
Unique webhook identifier.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
string
The HTTPS endpoint Nuvion delivers events to. Must use the
https protocol.number
Duration in seconds until the webhook expires. After expiry, no further events are delivered and the webhook status becomes
inactive.object
The set of events this webhook is subscribed to.
string[]
Read-only. A flattened summary of the enabled events, using
group.all where every event in a group is enabled. e.g. ["accounts.all", "outflows.all"].string
System-generated signing secret. Nuvion derives an HMAC from this value to sign each delivery. Returned once, at creation or when rotated via
rotate_secret: store it securely before leaving the page. It is never returned on subsequent requests. See Verifying signatures for how to validate incoming requests.string
Optional short description to identify the webhook in the dashboard.
string[]
Optional list of tags for organizing webhooks.
string
Webhook status. One of
active or inactive. Defaults to active at creation.number
Unix timestamp in milliseconds when the webhook was created.
number
Unix timestamp in milliseconds when the webhook was last updated.
number
0 if the webhook is active. Non-zero if the webhook has been deleted.object
Read-only delivery statistics for this webhook.
Example
Create a webhook
POST /entity-webhooks
Registers a new webhook endpoint for the authenticated entity.
Request parameters
string
required
The HTTPS endpoint Nuvion posts events to. Must begin with
https://. Invalid URLs or non-HTTPS URLs are rejected.number
required
Duration in seconds until the webhook expires. After expiry, deliveries stop and the webhook status becomes
inactive.string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
object
required
The events to subscribe to. Set
all to subscribe to every event, or enable specific events within one or more groups. See enabled_events fields for the full group structure.boolean
When
true, subscribes to every event type. Overrides all other selections in this object.Response
Returns201 Created with the new webhook object.
Update a webhook
PATCH /entity-webhooks/:id
Updates an existing webhook. Only the fields you include are changed; omitted fields retain their current values.
Path parameters
string
required
The ID of the webhook to update.
Request parameters
string
New HTTPS delivery URL. Must begin with
https://.boolean
Whether to rotate the webhook’s signing secret. Defaults to
false.string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
Set
rotate_secret to true if you’re rotating your secret key. The new value is returned once in the response, the same as at creation; it isn’t returned on later requests.Response
Returns200 OK with the updated webhook object.
Get a webhook
GET /entity-webhooks/:webhookId
Retrieves a single webhook by ID.
Path parameters
string
required
The ID of the webhook to retrieve.
Query parameters
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
Response
Returns200 OK with the webhook object.
Response
List webhooks
GET /entity-webhooks
Returns a paginated list of all webhooks for the authenticated entity.
Query parameters
integer
Number of results per page. Between
1 and 100. Defaults to 20.string
ULID pagination cursor from a previous response. Omit for the first page.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
Response
Returns200 OK with a paginated list of webhook objects.
Response
Delete a webhook
DELETE /entity-webhooks/:webhookId
Permanently deletes a webhook. Nuvion stops delivering events to the endpoint immediately.
Path parameters
string
required
The ID of the webhook to delete.
Request parameters
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
Response
Returns200 OK confirming deletion.
Response
The Webhook Log object
Each delivery attempt is recorded as a log entry. Logs are immutable and retained regardless of delivery outcome.string
Unique log entry identifier.
string
The ID of the entity this log belongs to.
string
The ID of the event that triggered this delivery.
string
The ID of the webhook that triggered this delivery.
string
The URL this delivery was sent to at the time of the attempt.
object
The request Nuvion sent to the webhook endpoint.
object
The response received from the webhook endpoint.
object
Timestamps for the delivery lifecycle.
number
Unix timestamp in milliseconds when the log entry was created.
number
Unix timestamp in milliseconds when the log entry was last updated.
number
0 for all log entries. Logs are immutable and never deleted.List webhook logs
GET /webhook-logs
Returns a paginated list of delivery log entries for the authenticated entity.
Query parameters
integer
Number of results per page. Between
1 and 100. Defaults to 20.string
ULID pagination cursor from a previous response. Omit for the first page.
string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
Response
Returns200 OK with a paginated list of log objects.
Response
X-Nuvion-Event-Signature and the other delivery headers are recorded as sent. See Verifying signatures for how to validate them.Send a test event
POST /webhook-tests
Sends a test delivery to an existing webhook endpoint, so you can verify it’s reachable and correctly signs and receives deliveries without waiting for a real event.
Request parameters
string
required
The ID of the webhook to send the test event to.
string
required
The event group to simulate. One of
entities, accounts, account_details, inflows, outflows, funding_sessions, payment_intent, payment_dispute, payment_refund, or cards.string
required
The specific event to simulate within the group. One of
created, updated, deleted, completed, failed, cancelled, refunded, frozen, or unfrozen.Not all combinations of event_group and event_name are valid. For example, funding_sessions.created does not exist. Refer to the enabled_events structure for supported combinations.string
The ID of the entity this webhook belongs to. Defaults to the authenticating entity when omitted. Required when acting on a child entity. See Managing child entities for details.
Response
Returns201 Created confirming the test was dispatched.
Response
The test delivery’s body only contains Use this endpoint to confirm your webhook is reachable and that your signature verification works, not to test your handler’s parsing logic against realistic event data. See Event types for real payload shapes.
event_group and event_name, not the full event/data shape a real event payload has:What’s next
Webhooks overview
Delivery model, retries, idempotency, and signature verification.
Event types
Full payload schemas and examples for every event.
