Update Webhooks or notification url

LedgerBlock uses a notification URL (webhook) to send transaction updates to your application.

You need to configure a notification URL so LedgerBlock knows where to deliver these notifications. A webhook secret is also provided during setup and is used to verify that incoming notifications are genuinely from LedgerBlock.

Why This Is Required

Configuring a notification URL allows your application to receive transaction updates without continuously polling the LedgerBlock API.

The webhook_secret adds an additional layer of security by allowing your application to verify the authenticity of incoming notifications.

Sample Request ; Update Notification URL

PUT {{base_url}}/api/v1/merchant/notificationurl

Request Headers

NameTypeDescription
Authorization*StringBearer ${api_key} — your activated merchant API key.

Request Body

NameTypeDescription
notification_urlStringYour webhook URL where LedgerBlock will send transaction notifications.
webhook_secretStringA secret key used to verify that notifications are genuinely sent from LedgerBlock.

Sample Request

{
  "notification_url": "https://webhook.site/030de34e-80b7-4860-a97f-eab867679bc8",
  "webhook_secret": "emcode_2026"
}

Webhook Verification

LedgerBlock signs webhook notifications using HMAC-SHA512.

The generated signature is included in the request header:

x-ledgerblock-signature

Why Webhook Verification Is Required

Webhook verification helps your application confirm that a notification was sent by LedgerBlock and that the notification payload has not been tampered with.

When your application receives a notification, use the configured webhook_secret to generate the HMAC-SHA512 signature and compare it with the value provided in the x-ledgerblock-signature header.

Only process the notification when the signatures match.

Verification Flow

Receive webhook → Read x-ledgerblock-signature → Generate HMAC-SHA512 using webhook_secret → Compare signatures → Process notification


Did this page help you?