Skip to main content
POST
Register Webhook

Authorizations

x-api-key
string
header
required

EASYCRED Partner API Key

Headers

x-api-key
string
required

Your active EASYCRED Partner API Key (format: ec_live_... or ec_test_...)

Example:

"ec_live_abc123_xyz789"

x-timestamp
string
required

Unix epoch seconds. Requests outside the 5-minute tolerance window are rejected.

Example:

"1759820800"

x-nonce
string
required

Unique UUID v4 nonce per request to prevent replay attacks.

Example:

"d3b07384-d113-4ec4-9d45-2f928e123456"

x-signature
string
required

HMAC-SHA256 signature calculated over method, path, timestamp, nonce, and raw request body.

Example:

"a1b2c3d4e5f67890123456789abcdef0123456789abcdef0123456789abcdef0"

Body

application/json
url
string<uri>
required
Example:

"https://partner.yourdomain.com/api/webhooks/easycred"

events
string[]
required
Example:

Response

Webhook registered successfully

success
boolean
required
Example:

true

data
object
required