Payonclick Developer Docs
v1

Webhook Events

Events pushed to your endpoint when a transaction changes status, and how to verify them.


Register an HTTPS endpoint under Developer › Webhooks and Payonclick sends an event when a transaction you created through the API changes status, usually within 15 seconds. That includes changes made after your call returned: a bill payment the status check settles later, or a transfer an operator completes hours afterwards.

EventSent whenPayload fields
bill.pendingA BBPS payment made through the API is waiting for biller confirmationreference_id, client_reference, status, amount, biller_id, biller_name, category, customer_reference, bbps_txn_id, approval_ref, response_code, message, refunded, created_at, updated_at
bill.successThe biller confirmed a BBPS paymentreference_id, client_reference, status, amount, biller_id, biller_name, category, customer_reference, bbps_txn_id, approval_ref, response_code, message, refunded, created_at, updated_at
bill.failedA BBPS payment failed; the wallet debit was reversedreference_id, client_reference, status, amount, biller_id, biller_name, category, customer_reference, bbps_txn_id, approval_ref, response_code, message, refunded, created_at, updated_at
bill.refundedA BBPS payment was reversed and refunded after reviewreference_id, client_reference, status, amount, biller_id, biller_name, category, customer_reference, bbps_txn_id, approval_ref, response_code, message, refunded, created_at, updated_at
transfer.pendingA DMT transfer made through the API is waiting for a transfer operatorrequest_id, client_reference, status, amount, charge_amount, total_debit, utr_number, failure_reason, refund_amount, beneficiary_name, beneficiary_bank_name, beneficiary_account_masked, beneficiary_ifsc, created_at, completed_at, refunded_at
transfer.successA transfer was completed; utr_number is setrequest_id, client_reference, status, amount, charge_amount, total_debit, utr_number, failure_reason, refund_amount, beneficiary_name, beneficiary_bank_name, beneficiary_account_masked, beneficiary_ifsc, created_at, completed_at, refunded_at
transfer.failedA transfer failed; the held amount is released to your walletrequest_id, client_reference, status, amount, charge_amount, total_debit, utr_number, failure_reason, refund_amount, beneficiary_name, beneficiary_bank_name, beneficiary_account_masked, beneficiary_ifsc, created_at, completed_at, refunded_at
transfer.refundedA transfer amount was refunded to your walletrequest_id, client_reference, status, amount, charge_amount, total_debit, utr_number, failure_reason, refund_amount, beneficiary_name, beneficiary_bank_name, beneficiary_account_masked, beneficiary_ifsc, created_at, completed_at, refunded_at
recharge.pendingA mobile/DTH recharge made through the API is with the operatorreference_id, client_reference, status, service, operator_id, operator_name, number, amount, total_debit, operator_ref, message, failure_code, refunded, created_at, updated_at
recharge.successThe operator confirmed a recharge; operator_ref is setreference_id, client_reference, status, service, operator_id, operator_name, number, amount, total_debit, operator_ref, message, failure_code, refunded, created_at, updated_at
recharge.failedA recharge failed; the wallet debit is released back to youreference_id, client_reference, status, service, operator_id, operator_name, number, amount, total_debit, operator_ref, message, failure_code, refunded, created_at, updated_at
aeps.pendingAn AEPS cash withdrawal, Aadhaar Pay or cash deposit is awaiting bank confirmationreference_id, client_reference, merchant_ref, service, status, amount, aadhaar, bank_iin, bank_name, bank_rrn, account_balance, charge, commission, wallet_impact, failure_code, message, refunded (CD), created_at
aeps.successAn AEPS transaction succeeded; bank_rrn is set and your AEPS wallet is settledreference_id, client_reference, merchant_ref, service, status, amount, aadhaar, bank_iin, bank_name, bank_rrn, account_balance, charge, commission, wallet_impact, failure_code, message, refunded (CD), created_at
aeps.failedAn AEPS transaction failed; a cash deposit is refunded to your AEPS walletreference_id, client_reference, merchant_ref, service, status, amount, aadhaar, bank_iin, bank_name, bank_rrn, account_balance, charge, commission, wallet_impact, failure_code, message, refunded (CD), created_at
upicw.successThe customer paid a UPI Cash QR; hand over the cash — your AEPS wallet is creditedreference_id, client_reference, merchant_ref, status, amount, customer_mobile, payer_vpa (masked), payer_name, bank_rrn, charge, commission, wallet_impact, failure_code, message, created_at, updated_at
upicw.failedA UPI Cash QR was not paid (expired or declined by the payer's bank)reference_id, client_reference, merchant_ref, status, amount, customer_mobile, payer_vpa (masked), payer_name, bank_rrn, charge, commission, wallet_impact, failure_code, message, created_at, updated_at
matm.successThe bank network confirmed a Micro ATM transaction; a cash withdrawal is credited to your AEPS walletreference_id, client_reference, merchant_ref, service, status, amount, card (masked), card_type, bank_name, bank_rrn, account_balance, mini_statement, charge, commission, wallet_impact, confirmed_by_bank_network, failure_code, message, created_at, updated_at
matm.failedA Micro ATM transaction failed or was declined; nothing is creditedreference_id, client_reference, merchant_ref, service, status, amount, card (masked), card_type, bank_name, bank_rrn, account_balance, mini_statement, charge, commission, wallet_impact, confirmed_by_bank_network, failure_code, message, created_at, updated_at
beneficiary.addedA beneficiary was added through the APIbeneficiary_id, bene_name, account_masked, bank_name, ifsc_code, is_verified
beneficiary.deletedA beneficiary was removed through the APIbeneficiary_id

Delivery

Each delivery is a POST with the JSON body {"event", "webhook_id", "delivery_id", "timestamp", "data"} and the headers X-POC-Event, X-POC-Delivery-Id, X-POC-Attempt and X-POC-Signature. Reply with any 2xx status within 10 seconds; redirects are not followed.

⚠️
At least once

A failed delivery is retried after 1 min, 5 min, 15 min, 1 h, 3 h and 6 h, with the same X-POC-Delivery-Id, so the same event can arrive more than once: de-duplicate on the delivery id. Every failed attempt raises the failure count of the webhook and a success resets it. A webhook announces a change; call the status endpoint when you need the current state of a transaction.

Verifying a delivery

Deliveries are signed with your webhook secret in the X-POC-Signature header as sha256=<hmac>, computed over the raw body. Verify it before trusting the payload.

import hmac, hashlib

def verify(raw_body: bytes, header: str, secret: str) -> bool:
    expected = hmac.new(secret.encode(), raw_body, hashlib.sha256).hexdigest()
    return hmac.compare_digest("sha256=" + expected, header)
📘
Endpoint requirements

The callback URL must use HTTPS and resolve to a public address; private, loopback and link-local addresses are refused. Acknowledge the delivery first and process it afterwards, so a slow job never causes a timeout.