Set Up Your Webhook
Webhook Payload
Every event delivers a JSON body with full transaction details. Below is an example payload for a completed withdrawal:Retry Policy
Finrock retries a failed delivery up to 5 times, with increasing delays between each attempt:
Design your handler to be idempotent — if the same event is delivered more than once due to a retry, processing it twice should not cause incorrect state in your system.
Webhook Authentication
All webhook requests include anx-signature header containing an RSA-SHA512 signature of the raw JSON payload body. Verify this signature using Finrock’s public key before processing any event.
Finrock Webhook Public Key:
Signature Verification
Use the following Node.js example to verify the signature in your webhook handler:Make sure your framework captures the raw request body as a string before any JSON parsing. Some frameworks (like Express with
express.json()) parse the body before your handler runs — use express.raw() or capture the raw buffer if your parsed and stringified JSON does not match the original byte sequence, which would cause signature verification to fail.