Create a webhook endpoint
const url = 'https://api.paywithnablr.com/v1/webhook-endpoints';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"url":"https://shop.example/webhooks/nablr","events":["payment.succeeded"],"active":true}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.paywithnablr.com/v1/webhook-endpoints \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "url": "https://shop.example/webhooks/nablr", "events": [ "payment.succeeded" ], "active": true }'The response carries the endpoint’s signing secret (whsec_…).
It is shown only here. Store it; you need it to check the
Nablr-Signature header. The endpoint belongs to the key’s mode.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
An absolute https URL on the public internet.
Example
https://shop.example/webhooks/nablrThe events to send. Omitted or empty means every event.
Responses
Section titled “Responses”The endpoint, with its secret.
object
object
The end of the signing secret, to tell secrets apart.
The signing secret. Shown only in this response.
object
This request’s id, also in the X-Request-Id header.
Example
{ "data": { "id": "whe_01M3XX9QZ6J4B1M2N3P4Q5R6S7", "object": "webhook_endpoint", "url": "https://shop.example/webhooks/nablr", "events": [ "payment.succeeded" ], "mode": "test", "secret_last4": "K1q4", "secret": "whsec_9xQ2vLk3TzN8bR4mW7pY1cF6hJ0sD5aE2gU8iO3nK1q" }}VALIDATION_FAILED: a field is wrong; details says which.
MALFORMED_REQUEST: the body is not valid JSON.
object
object
A sentence for a person. Safe to show to your user.
The code in words, for example Validation failed.
A quotable reference for some failures.
One entry per field that is wrong.
object
For example required, invalid, format, length, unknown, type.
Extra context, such as retry_after_seconds on RATE_LIMITED.
object
object
This request’s id, also in the X-Request-Id header.
Example
{ "error": { "message": "Send a positive amount in minor units (500000 = ₦5,000.00).", "code": "VALIDATION_FAILED", "title": "Validation failed", "details": [ { "field": "amount", "code": "invalid", "message": "Send a positive amount in minor units (500000 = ₦5,000.00)." } ] }, "meta": { "request_id": "01a0fbd4-3b18-7181-9149-8dbcae100085" }}UNAUTHENTICATED: no Authorization: Bearer header.
INVALID_API_KEY: the key is unknown, malformed or revoked.
object
object
A sentence for a person. Safe to show to your user.
The code in words, for example Validation failed.
A quotable reference for some failures.
One entry per field that is wrong.
object
For example required, invalid, format, length, unknown, type.
Extra context, such as retry_after_seconds on RATE_LIMITED.
object
object
This request’s id, also in the X-Request-Id header.
Example
{ "error": { "message": "The API key provided is not valid.", "code": "INVALID_API_KEY", "title": "Invalid API key" }, "meta": { "request_id": "01a0fbd4-3b68-75e0-bd33-0b950ddc99a5" }}SECRET_KEY_REQUIRED: you sent a publishable key.
LIVE_MODE_NOT_ENABLED: a live key before your business is verified.
ACCOUNT_RESTRICTED: the account is suspended.
object
object
A sentence for a person. Safe to show to your user.
The code in words, for example Validation failed.
A quotable reference for some failures.
One entry per field that is wrong.
object
For example required, invalid, format, length, unknown, type.
Extra context, such as retry_after_seconds on RATE_LIMITED.
object
object
This request’s id, also in the X-Request-Id header.
Example
{ "error": { "message": "This request needs your secret key. Publishable keys can only be used from a checkout.", "code": "SECRET_KEY_REQUIRED", "title": "Secret key required" }, "meta": { "request_id": "01a0fbd4-3b68-75e0-bd33-0b950ddc99a5" }}RATE_LIMITED: wait Retry-After seconds, then retry.
object
object
A sentence for a person. Safe to show to your user.
The code in words, for example Validation failed.
A quotable reference for some failures.
One entry per field that is wrong.
object
For example required, invalid, format, length, unknown, type.
Extra context, such as retry_after_seconds on RATE_LIMITED.
object
object
This request’s id, also in the X-Request-Id header.
Example
{ "error": { "message": "Too many attempts. Please wait a moment and try again.", "code": "RATE_LIMITED", "title": "Rate limited", "meta": { "retry_after_seconds": 12 } }, "meta": { "request_id": "01a0fbd4-3b68-75e0-bd33-0b950ddc99a5" }}Headers
Section titled “Headers”Seconds to wait.
Unix time when a request will be allowed again.