Skip to main content
Webhooks are event-based notifications that are received when a specific event related to the reverse penny drop verification occurs.
In rare cases, such as network retries, read timeouts, processing delays, or delivery failures, the same webhook might be sent more than once for the same event. To prevent unintended side effects, implement idempotency in your webhook handler to handle duplicate deliveries.

Add webhooks

Add your webhook URL in our system for us to deliver webhook events. Follow the instructions below to configure the webhook URL. Ensure to provide the publicly accessible HTTPS URL to your webhook endpoint.
  1. Log in to the Merchant Dashboard and click Developers.
  2. Click Webhooks listed under the Secure ID card.
  3. Click Add Webhook URL in the Webhook screen.
  4. In the Add Webhook popup, fill in the following information:
    • Webhook URL: Enter the URL in this field.
  5. Click Test & Add Webhook.

Add Webhook

Webhook event

The following events are triggered at different stages of the reverse penny drop verification process:

Webhook payload fields

The webhook payload contains important metadata in its top-level fields.

Signature Verification

Verifying the signature is mandatory before processing any response. It helps authenticate that the webhook is from Cashfree Payments. Follow the steps to verify the signature:
  1. Sort the array based on keys.
  2. Concatenate all the values in this array and the resultant is the post data (postData).
  3. Encrypt the postData with SHA-256 and Base64-encode it.
  4. Verify that the calculated signature matches the signature received.
  5. Continue processing only if the signatures match. Otherwise, discard the request.
  6. Ensure that the clientSecret you use belongs to the oldest active key pair.
For example, from the webhook received, extract the data and pass it to generate HMAC function:
Java code - for reference

IPs to whitelist

When you decide to consume the webhooks, first, you need to verify if your systems need an IP whitelisting to be done at your end or not. Accordingly you can whitelist the below IPs of Cashfree: