Hash in x-ledgerblock-signature
The webhook payload is hashed to generate a unique signature for the request. The hash is generated using the webhook secret associated with your LedgerBlock account.
Your application should always generate the hash from the raw request payload received from LedgerBlock. Changing, formatting, or re-serializing the JSON before generating the hash may result in a different signature.
x-ledgerblock-signature
LedgerBlock includes the generated webhook signature in the x-ledgerblock-signature header.
Your application should use this header to verify the authenticity of every webhook request before processing the event.
Example header:
x-ledgerblock-signature:
Do not process a webhook before its signature has been successfully verified.
Collection Webhook
The Collection Webhook notifies your application about events related to incoming payments or collections.
When a collection transaction reaches a relevant state, LedgerBlock sends a webhook request to your configured collection webhook URL.
Your application should:
Receive the webhook request.
Verify the x-ledgerblock-signature.
Validate the event data.
Process the collection according to the transaction status.
Return a successful HTTP response to acknowledge receipt.
The collection webhook should be treated as the source of transaction status updates rather than assuming that a transaction is successful immediately after initiating it.
Payout Webhook
The Payout Webhook notifies your application about events related to outgoing payments or payouts.
When a payout transaction reaches a relevant state, LedgerBlock sends a webhook request to your configured payout webhook URL.
Your application should:
Receive the webhook request.
Verify the x-ledgerblock-signature.
Validate the event data.
Process the payout according to the transaction status.
Return a successful HTTP response to acknowledge receipt.
The payout webhook allows your application to update the status of a payout without repeatedly polling the payout endpoint.
Webhook Security
Always verify the x-ledgerblock-signature before processing a webhook. Your webhook endpoint should also be publicly reachable over HTTPS and should return an appropriate success response after successfully processing the event.
Updated 27 days ago

