Unlock on your product
Register, list, test, or delete HTTPS webhook endpoints. payment.succeeded is how Accept connects to your backend.
Same flow over HTTP: Webhooks API
Tool
rill_webhooksUse action=create to register a callback for payment.succeeded so your product can grant access after pay. Delivery is signed and SSRF-safe. Use action=list to review registered endpoints. action=test sends a sample event. action=delete removes the endpoint. Save the signing secret from the create response, you need it to verify X-Rill-Signature.
Auth
Parameters
Usage notes
- Verify HMAC-SHA256 of {X-Rill-Webhook-Id}.{X-Rill-Timestamp}.{raw body} as X-Rill-Signature: v1,<hex>, 300s window. Scheme and a payment.succeeded example: /docs/api/webhooks.
- Localhost callbacks are allowed outside production.
- Same flows over HTTP: POST /webhooks, GET /webhooks, POST /webhooks/:id/test, DELETE /webhooks/:id. CLI twin: webhooks create|list|test|delete.