Skip to main content
Webhooks let your backend application react to deposit and withdrawal events the moment they happen, without polling the Finrock API. When you register a webhook URL, Finrock sends an HTTP POST request to that URL every time a transaction event occurs in your workspace — including new deposits, withdrawal confirmations, and status changes.

Set Up Your Webhook

Webhook Payload

Every event delivers a JSON body with full transaction details. Below is an example payload for a completed withdrawal:
Key fields to note:

Retry Policy

Your webhook endpoint must return an HTTP 200 status code to acknowledge successful receipt. If Finrock receives any other response code — or no response within the timeout window — it marks the delivery as failed and retries.
Finrock retries a failed delivery up to 5 times, with increasing delays between each attempt: Design your handler to be idempotent — if the same event is delivered more than once due to a retry, processing it twice should not cause incorrect state in your system.

Webhook Authentication

All webhook requests include an x-signature header containing an RSA-SHA512 signature of the raw JSON payload body. Verify this signature using Finrock’s public key before processing any event. Finrock Webhook Public Key:

Signature Verification

Use the following Node.js example to verify the signature in your webhook handler:
Always verify the x-signature header before processing a webhook event. This confirms the request genuinely originated from Finrock and has not been tampered with in transit.
Make sure your framework captures the raw request body as a string before any JSON parsing. Some frameworks (like Express with express.json()) parse the body before your handler runs — use express.raw() or capture the raw buffer if your parsed and stringified JSON does not match the original byte sequence, which would cause signature verification to fail.