webhook:bootstrap and call POST /v1/webhook-endpoints with Idempotency-Key and {"url":"https://merchant.example/webhooks/tly"}. This URL is illustrative. Use your real registered HTTPS domain, port 443, and no credentials, query string or fragment. The sender does not follow redirects.resource_id and one-time secret securely. A repeated setup response may omit secret. Keep the Secret you have already saved. If a retry does not return a Secret and you did not save one, rotate the Secret in your dashboard before using the endpoint. Verify saved API setup credentials with POST /v1/webhook-endpoints/{webhook_endpoint_id}/verify and {"secret":"<WEBHOOK_SECRET>"}.secret_kind identifies an active or pending signing Secret. For rotation, open the Webhook detail under Integrations > Webhooks, choose Rotate Secret > Generate new Secret, and save the new signing Secret. Update your receiver to accept the pending signing Secret, then choose Activate rotated Secret > Activate Secret. The old signing Secret stays active until this explicit switch; afterward the sender uses only the new active signing Secret. A bounded receiver overlap can accept requests already in flight with the old signature.schema_version, event_id, event_type, occurred_at and data. The event is payment.updated; creation, first Checkout activation and disabling Checkout access do not emit it. Updates, accepted amount changes, payment outcomes, expiration, cancellation and review can emit it.max_skew_secs in your receiver configuration and pass the current trusted Unix time as now_secs. Your HTTP framework must retrieve these case-insensitive headers correctly.event_id, and compare data.status_version only with the same Payment's stored version. Duplicate or stale facts must not overwrite newer facts. Return 2xx after accepting responsibility for the event. This example verifies the message only; it does not provide durable storage or fulfill an order.2xx acknowledges delivery, not a paid order. Use the authoritative Payment query when you need to recover missing payment facts.2xx acknowledges delivery. Network failures, 408, 425, 429 and 5xx receive finite retries; other non-2xx results are permanent failures. A redirect is not an acknowledgment.GET /v1/payments/{payment_id} with payment:read. Querying does not change delivery state. Open Integrations > Webhook log, select a delivery to inspect its status and attempts, and use Replay Delivery > Queue replay when you have permission to retry a delivery. Replay queues the same event again for the active Webhook, preserving its Event ID and original envelope. Delivery timestamps and signatures are generated for the new attempt. A queued replay is not proof that the receiver accepted it.