Skip to main content

Signing

If the merchant has configured a webhook secret, each request carries:
  • X-Novacrust-Signature — HMAC-SHA256 of ${timestamp}.${JSON.stringify(payload)}, using the merchant’s webhook secret.
  • X-Novacrust-Timestamp — the timestamp used in the signature above.
If no webhook secret is configured, requests are sent unsigned.

Payouts

Events: PAYOUT_SUCCESS, PAYOUT_FAILED. There is no “initiated” or “pending” payout webhook — only these two terminal states are ever sent. Envelope: { event, data: {...} }.

PAYOUT_SUCCESS (fiat)

PAYOUT_FAILED (fiat)

Identical field set to PAYOUT_SUCCESS — only status, sent_status, and event change to "FAILED".

Crypto payouts — extra fields on success only

A crypto withdrawal PAYOUT_SUCCESS payload adds three fields not present on fiat payouts or on crypto PAYOUT_FAILED:
Note: this asymmetry (crypto success gets network_txid/network_fee/network, crypto failure does not) reflects current live behavior, not an intentional design choice documented elsewhere — flagging in case it should be made symmetric in a future change.

Field reference