Skip to main content
Webhooks allow your application to receive real-time HTTP push notifications when the status of a transaction changes (for example, when a mobile money collection is approved or failed).

Configuring Webhooks

You can configure your Webhook URL in the PayX Dashboard under Developer Settings. Once configured, PayX will send an HTTPS POST request with JSON payloads to your endpoint whenever transaction events occur.

Security & Delivery Rules

To protect merchant systems and prevent security vulnerabilities, PayX enforces strict outbound webhook rules:
HTTPS & SSRF Protection:
  • Webhook destinations must use public HTTPS endpoints on port 443 (e.g., https://api.yourdomain.com/webhooks).
  • Destinations targeting localhost, loopback addresses (127.0.0.1, ::1), private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), or non-443 ports are blocked to prevent Server-Side Request Forgery (SSRF).
  • For local testing, use a tunneling tool such as ngrok or Cloudflare Tunnels to expose a public HTTPS URL.

Signature Verification

Every webhook request contains an X-PayX-Signature header. This is an HMAC-SHA256 signature generated using your Webhook Secret (whsec_live_... or whsec_test_...) and the raw HTTP request body. You should always verify this signature before processing events.

Verifying with Node.js SDK

If you are using the payx-node SDK:

Manual Verification (Standard Node.js Crypto)


Event Payloads

1. transaction.success

Sent when a payment or payout has successfully completed.

2. transaction.failed

Sent when a transaction fails (e.g., customer cancelled USSD prompt, insufficient wallet balance, or network timeout).