Configure Payment Webhooks

Configure provider payment events, signature verification, transaction mapping, retries, and duplicate protection.

STEPS

  1. Copy the Wemblo payment webhook URL.
  2. Open the provider's webhook settings.
  3. Create the endpoint and select required payment events.
  4. Create or copy the webhook secret.
  5. Enter the secret in Wemblo.
  6. Send a provider test event.
  7. Confirm signature verification and transaction update.
  8. Confirm duplicate events do not create duplicate orders or activations.

Who should use it

Workspace owners, operations teams, sales users and authorized technical users.

Where to find it in Wemblo

Wemblo -> My Subscription -> Payment Gateway / Payment Transactions

Before you begin

  • Use the correct workspace and authorized role.
  • Prepare fictional Pakistan test data.
  • Confirm connected provider accounts where required.
  • Define who approves price, stock, booking, payment or final status.

Main concepts and fields

Concept / FieldMeaning or Use
EndpointHTTPS URL receiving an event.
AuthenticationKey or secret protecting the request.
Event IDUnique event reference.
IdempotencyPrevents duplicate processing.
MappingConnects event data to Wemblo fields.

Test and verification

  1. Complete one successful path with fictional data.
  2. Complete one invalid, failure or permission path.
  3. Confirm the result appears in the correct workspace and module.
  4. Confirm the correct person or team can review and continue the work.

Common issues and solutions

IssueWhat to Check
Configuration does not saveRequired fields, validation, permission and active workspace.
External action failsCredential, provider status, endpoint or field mapping.
Duplicate record or actionEvent ID, idempotency, retries and existing record.
Customer notification is missingTemplate, channel connection, status transition and contact details.

Security, privacy, consent, cost and provider notes

  • Use only data the business is authorized to process.
  • External provider charges, policies, approvals, limits and availability remain separate.
  • Do not expose passwords, API keys, tokens, webhook secrets, payment credentials or private customer data.
  • Use human review for sensitive, regulated, urgent, financial or final decisions.

Last reviewed: