Skip to main content
POST
Receive an issuer card-tokenization webhook

Headers

card-issuer-signature
string | null
card-issuer-signature-timestamp
string | null
X-Timestamp-Format
string

Controls how timestamp fields are serialized in JSON response bodies.

Default (header omitted or any other value): epoch milliseconds as integers. iso8601: UTC ISO 8601 strings of the form YYYY-MM-DDTHH:MM:SSZ.

Example: with X-Timestamp-Format: iso8601, the field value 1704067200000 becomes "2024-01-01T00:00:00Z".

Affected fields (recursively, in dicts and arrays): any field whose name ends in _at, plus the literal field names timestamp, period_start, and period_end. All other fields are passed through unchanged.

Only iso8601 is recognized. Any other value (or omitting the header) yields the default epoch-ms representation; the server does not reject unknown values, so this is documented as an example rather than an enum to keep generated clients permissive.

Example:

"iso8601"

Body

application/json
eventId
string
required

Unique identifier for the webhook delivery, used for replay dedup.

cardExternalId
string
required

Server-owned reference identifying the card the material belongs to.

card
object
required

Response

Webhook received

Acknowledgement returned for every accepted webhook delivery (incl. no-op replays).

received
boolean
default:true