1. Card Present Billpocket
  • API Docs Mexico 🇲🇽
  • Online Payments
    • Release Notes
    • Card Payments
      • Request a card token
      • Make a charge or deferred charge
      • Create payment (tokenless)
      • Request deferred options
      • Refund a transaction
      • Authorize payments
      • Preauthorization (tokenless)
      • Void a transaction
      • Reauthorize payments
      • Capture an authorized payment
      • Bin Info V2
      • Bin Info
      • Validate OTP
    • One-Click and Scheduled Payments
      • Request a recurring charge token
      • Create a recurring charge
      • Make an One-click payment
      • Update recurring charge card data
      • Cancel a recurring charge
      • Update a recurring charge
      • Add a temporary charge or discount
      • Authorize payments
      • Capture an authorized payment
      • Get recurring charge Info
    • Transfer in
      • Get Bank List
      • Request a Transfer In token
      • Init Transaction
      • Get Status
    • Transfer Out
      • Get Bank List
      • Get Bank List V2
      • Request a Transfer Out token
      • Init Transaction
      • Get Status
      • Balance for Payouts
    • Smartlinks
      • Create a Smartlink
      • Get a Smartlink
      • Delete a smartlink
      • Update a Smartlink
    • Payment Button
      • Create a payment button
    • Analytics
      • Get transactions list v1
      • Get transactions list v2
    • Chargebacks
      • Query Chargebacks
      • Request Chargeback Export
    • Commissions
      • Get Commission Configuration
    • Payment Credentials
      • Create a credential
      • Activate or deactivate
      • Delete credential
      • Regenerate a credential
      • Update credential
      • Advanced search
      • Search credentials
    • Platform Status
      • Get platform status
      • Get gateway status
    • Settlement
      • Query settlement
    • Subscription Transactions
      • Get subscription transactions
  • Card Present Billpocket
    • Get Started
      • Create Account
      • User Token
      • API Keys
    • Webhooks
      • Webhooks — Transfer Funds to Your Bank Account
      • Transfer Funds Errors
    • Terminals
      • App Review
      • Splash Screen
    • Card Present Payment Services
      • Cloud Terminal API
        • Collect card payments
        • Print Ticket
        • Cancel Push Notification
        • Get transaction status
        • Collect card payments v2
      • App-to-App
        • Android intents
        • App to App — iOS
        • App to App — Mobile Web
      • Terminal SDK
        • Terminal SDK Android
        • Android SDK errors
    • Card not Present Billpocket Services
      • 3DS Checkout
        • Create checkout
        • Get checkout details
      • E-commerce Flex
        • Get token
        • Validate token
        • Collect payments
        • Refund
        • Capture an authorized payment
        • Get status
    • Catalogs
      • States
      • Municipalities
      • Tax companies
      • Commercial activities
    • User Settings
      • Create user
    • Accounts
      • Clabe Account Setup
        • Add CLABE account
      • Deposit Accounts
        • Add or update CLABE account
    • Transactions
      • Transaction List
        • Get token
        • Get transaction list
        • Get transaction list v2
        • Get transaction list v3
        • Get transaction list v4
      • Cancel Payments
        • Cancel payments Error Codes
        • Cancel payments
  • API Raw Card Present
    • The Amount Object
    • Error Catalog
    • Key Exchange Process
    • Release Notes
    • Test Data
    • One-time payments
      • Single payment
    • Two-step-payments
      • Authorization and capture
    • Voids & Refunds
      • Refund a transaction
      • Void & Reverse
    • Card information
      • Get BIN Info
      • Bin Info V2
      • Request deferred options
    • Query Transactions
      • Transaction Search
    • Webhooks
      • Webhooks — Introduction
      • Good Practices
      • Webhooks — Card Payments
      • Webhooks — Refunds
      • Check Your Webhooks
    • Chargebacks
      • Query Chargebacks
      • Request Chargeback Export
  • Kushki One
    • Error Catalog
    • Release notes
    • Transaction Examples
    • Webhooks
    • Cloud Services
      • Payment
        • Sync
          • Charge
          • Authorization (Pre-auth)
          • Capture
          • Re-authorization
          • Post-tip
          • Void
          • Refund
          • Abort
        • Async
          • Charge (Async)
          • Authorization — Pre-auth (Async)
          • Capture (Async)
          • Re-authorization (Async)
          • Post-tip (Async)
          • Void (Async)
        • Search
          • Transaction Search
      • Print
        • Create Print Job
        • Get Print Job Status
    • Local Services
      • Payment
        • Sync
          • Charge
          • Authorization (Pre-auth)
          • Capture
          • Re-authorization
          • Post-tip
          • Void
          • Refund
          • Abort
        • Async
          • Charge (Async)
          • Authorization — Pre-auth (Async)
          • Capture (Async)
          • Re-authorization (Async)
          • Post-tip (Async)
          • Void (Async)
          • Abort (Async)
        • Search
          • Transaction Search — Online
          • Transaction Search — Local
      • Print
        • Create Print Job
        • Get Print Job Status
        • Print Job Webhook (inbound — implemented by your POS)
  • Appian - Submerchant Register
    • Submerchant Validation in Batch
    • Query submerchant status by requestId/submerchantId
    • Submerchant Document Upload
    • Get submerchantIds
    • Get credentials for submerchants
  • Schemas
    • RequestBodies
      • one-and-two-step-payment
    • Card
    • Channel
    • Amount-cash-in
    • ChargebackListResponse
    • StatusComponent
    • SettlementDateRangeRequest
    • SubscriptionTransactionsResponse
    • amount
    • TransactionResponse
    • PrintJobRequest
    • one-and-two-step-payment-2
    • networkToken
    • ChargebackItem
    • SubscriptionTransaction
    • extra_taxes
    • RawResponse
    • CommandText
    • currency
    • ErrorResponse400
    • ErrorResponse
    • SettlementResponse
    • SettlementRecord
    • webhooksItem
    • card
    • CardData
    • CommandColumns
    • Amount
    • Country
    • ErrorResponse401
    • card_details
    • LinkFailure
    • ColumnItem
    • extraTaxes
    • ErrorResponse403
    • enc_tlv
    • CommandDivider
    • TransactionEvent
    • Deferred
    • payment_method
    • ErrorResponse500
    • deferred
    • CommandFeed
    • TransactionStatus
    • pos_details
    • CommandSpace
    • ReadingType
    • ContactDetails
    • contact_details
    • sub_merchant
    • CommandCut
    • FailureReason
    • documentType
    • Subscription
    • metadata
    • CommandImage
    • EventTerminal
    • orderDetails
    • Language
    • TransactionSearchRequest
    • CommandQR
    • EventOperation
    • Shipping Address
    • payment_submethod
    • CommandBarcode
    • EventAmount
    • Billing-Address
    • SubscriptionUpdate
    • EventExtraTaxes
    • PrintJobAccepted
    • product
    • SubscriptionAdjustmentRequest
    • PrinterError
    • EventMetadata
    • threeDomainSecure
    • AmountWithTaxes
    • PrintJobStatus
    • PrintJobStatusRequest
    • webhooks
    • AmountCore
    • headers
    • ExtraTaxes
    • PrintWebhookPayload
    • Metadata
    • webhooksChargeback
    • citMit
    • AmountWithTip
    • network
    • TransactionSearchBody
    • TransactionSearchOnlineBody
    • binInfo
    • AmountWithOptionalTip
    • TransactionSearchLocalBody
    • messageFields
    • TransactionEvent_2
    • UnexpectedErrorResponse
    • FailureReason_2
    • transactionType
    • ExternalReferenceId
    • EventTerminal_2
    • ExternalSubscriptionId
    • EventOperation_2
    • EventAmount_2
    • EventExtraTaxes_2
    • EventMetadata_2
    • SettlementTicketRequest
BienvenidaPerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
BienvenidaPerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
  1. Card Present Billpocket

Webhooks

Webhooks allow you to subscribe to events that may occur, such as a transaction being approved or declined. When an event is triggered, we notify you through an endpoint that you have previously configured, sending a POST request with a JSON object containing all the necessary information about the event.
Using webhooks, your application can listen for important events and trigger actions, such as updating the database when a payment is successfully processed within your system.
INFO
Webhooks are asynchronous. Notifications are usually sent immediately, but occasional delays can occur. Design your integration to handle delayed or out-of-order delivery.

Endpoint requirements#

Before configuring an endpoint to receive notifications, it must meet the following requirements:
Accept HTTP POST requests
Have a valid SSL certificate (HTTPS) and public access
Respond with HTTP 200 (OK) within 2 seconds
Accept payloads in JSON format
Have a URL no longer than 300 characters

Event types#

EventDescription
Approved transactionsFired when a card payment is approved.
Rejected transactionsFired when a card payment is declined.
RefundsFired when a refund is approved, rejected or left pending.
Transfer funds to your bank accountSPEI settlement notification for funds transferred to your bank account.
Depending on the type of event that triggers a notification, you receive an object with a certain structure in the payload.
To ensure that the requests you receive on your endpoint come from us, use the X-BP-Signature and X-BP-SignatureKey headers to authenticate the incoming request. See Security for details.

Register your endpoint#

1.
Log in to the dashboard with the correct credentials according to the environment.
2.
Navigate to Configuración > Integraciones.
3.
Enter your endpoint URL in the Webhook General section.
4.
Select the type of events you want to subscribe to.
5.
Click Guardar.
Note
The endpoint must respond with an HTTP Status Code 200 for it to be saved successfully. Changes may take a few minutes to take effect.
register-endpoint-webhook.png

Security#

A digital signature is provided with every POST notification. Signature values are accessible through the request headers:
HeaderDescription
X-BP-SignatureBase64-encoded value of the signature for the delivered payload.
X-BP-SignatureKeyKey index of the private key used to sign the message.
To get a hold of the public key for signature verification, append the key index to the following URL, using the .pem or .der extension depending on the preferred format for your application:
https://keys.billpocket.com/webhook/
Example — for key index k1:
PEM: https://keys.billpocket.com/webhook/k1.pem
DER: https://keys.billpocket.com/webhook/k1.der
INFO
We encourage you to cache or otherwise store the public key contents on your side to speed up the signature verification process on successive notifications. Keys won't change over time, but the key index may be updated to use a new pair of keys.

Code examples#

Below are code examples on how to receive event notifications through webhooks.
Java
PHP
Node.js
Assuming you're using Spring Boot, get the signature and signature key values to perform verification on the received payload:
The previous code has the following dependencies:
<dependency>
  <groupId>commons-io</groupId>
  <artifactId>commons-io</artifactId>
  <version>2.6</version>
</dependency>

<dependency>
  <groupId>org.bouncycastle</groupId>
  <artifactId>bcprov-jdk15on</artifactId>
  <version>1.54</version>
</dependency>

Approved transactions#

Configure webhook#

Log in with your account in the dashboard and select the Configuración > Integraciones option.
Set your webhook URL in the Webhook General section and select the Transacciones Aprobadas option under the Ventas tab. Click Guardar to save your changes.
Note
Changes may take a few minutes to take effect. The webhook URL must be no longer than 300 characters.
approved-transactions-webhook.png

Payload fields#

Below are all the properties that can be contained in the payload of an approved transaction event.
PropertyTypeDescription
resultStringTransaction result. Possible values: aprobada for approved transactions.
amountStringTransaction amount.
tipStringIf the transaction includes a tip, it is returned.
paymentsIntegerIf the transaction has been deferred, the number of deferred installments. For example, 3.
authorizationTimeStringAuthorization time. RFC 3339 date format.
referenceStringTransaction description.
transactionidStringTransaction ID generated by Kushki.
authorizationStringTransaction authorization string.
creditcardStringLast 4 digits of the card's Primary Account Number.
cardtypeStringCard issuer. Possible values: VISA, MASTERCARD, CARNET, AMERICAN EXPRESS.
arqcStringEMV only. Authorization Request Cryptogram (ARQC) of the transaction.
userIDIntegerID of the user who made the transaction.
aidStringEMV only. Chip's Application ID.
applabelStringEMV only. Chip's Application Label.
urlStringUnique identifier to access a transaction ticket.
emailStringEmail to which the transaction ticket is sent.
phoneStringPhone number to which the transaction ticket is sent.
cardBrandStringCard Issuer Network.
cardIssuerStringCard Issuer Bank.
cardCountryStringCard Country Code (ISO 3166-1 alpha-2).
cardClassStringDEBIT or CREDIT card.
launchTimeStringTime the transaction was sent.
maskedPANStringMasked card number.
uniqueReferenceStringUnique identifier per transaction generated on the client side to avoid duplicates. For example, a UUID.

Example#

{
    "cardBrand": "MASTERCARD",
    "cardIssuer": "SANTANDER",
    "cardCountry": "MX",
    "cardClass": "CREDIT",
    "launchTime": "2024-05-29T11:01:27.360-0600",
    "userID": 61000,
    "authorizationTime": "2024-05-29T11:01:27.360-0600",
    "result": "aprobada",
    "amount": "100.00",
    "payments": 0,
    "transactionid": "128010",
    "authorization": "BP3500",
    "creditcard": "0009",
    "cardtype": "MASTERCARD",
    "arqc": "A38051D19B2548E3",
    "aid": "A0000000041010",
    "applabel": "Mastercard",
    "url": "face3142cb4d32a545f42d278b8cf4ce5ea3d0b1",
    "maskedPAN": "500000******0009",
    "uniqueReference": "d6732f94-6cf2-4dfb-aed7-11b64b739407"
}

Rejected transactions#

Configure webhook#

Log in with your account in the dashboard and select the Configuración > Integraciones option.
Set your webhook URL in the Webhook General section and select the Transacciones Rechazadas option under the Ventas tab. Click Guardar to save your changes.
Note
Changes may take a few minutes to take effect.
rejected-transactions-webhook.png

Payload fields#

Below are all the properties that can be contained in the event payload of a rejected transaction.
PropertyTypeDescription
resultStringTransaction result. Possible values: rechazadaProsa for rejected transactions.
amountStringTransaction amount.
tipStringIf the transaction includes a tip, it is returned.
paymentsIntegerIf the transaction has been deferred, the number of deferred installments. For example, 3.
authorizationTimeStringAuthorization time. RFC 3339 date format.
referenceStringTransaction description.
transactionidStringTransaction ID generated by Kushki.
creditcardStringLast 4 digits of the card's Primary Account Number.
cardtypeStringCard issuer. Possible values: VISA, MASTERCARD, CARNET, AMERICAN EXPRESS.
arqcStringEMV only. Authorization Request Cryptogram (ARQC) of the transaction.
userIDIntegerID of the user who made the transaction.
aidStringEMV only. Chip's Application ID.
applabelStringEMV only. Chip's Application Label.
cardBrandStringCard Issuer Network.
cardIssuerStringCard Issuer Bank.
cardCountryStringCard Country Code (ISO 3166-1 alpha-2).
cardClassStringDEBIT or CREDIT card.
launchTimeStringTime the transaction was sent.
maskedPANStringMasked card number.
uniqueReferenceStringUnique identifier per transaction generated on the client side to avoid duplicates. For example, a UUID.
Note
Unlike approved transactions, rejections do not return authorization, url, email or phone.

Example#

{
    "cardBrand": "MASTERCARD",
    "cardIssuer": "SANTANDER",
    "cardCountry": "MX",
    "cardClass": "CREDIT",
    "launchTime": "2024-05-29T10:46:52.221-0600",
    "userID": 61000,
    "authorizationTime": "2024-05-29T10:46:52.221-0600",
    "result": "rechazadaProsa",
    "amount": "99.00",
    "payments": 0,
    "transactionid": "128011",
    "creditcard": "0009",
    "cardtype": "MASTERCARD",
    "arqc": "6FEC34124C9AAEEB",
    "aid": "A0000000041010",
    "applabel": "Mastercard",
    "maskedPAN": "500000******0009",
    "uniqueReference": "d6732f94-6cf2-4dfb-aed7-11b64b739407"
}

Refunds#

Configure webhook#

Log in with your account in the dashboard and select the Configuración > Integraciones option.
Set your webhook URL in the Webhook General section and select the Transacciones Aprobadas and/or Transacciones Rechazadas option in the Devoluciones tab. Click Guardar to save your changes.
Note
Changes may take a few minutes to take effect.
refund-webhook.png

Payload fields#

Below are all the properties that can be contained in the payload of an approved or rejected refund event.
PropertyTypeDescription
resultStringTransaction result. Possible values: aprobada for approved refunds; rechazadaRiesgo, rechazadaProsa or rechazada for rejected refunds; pendiente for pending refunds.
amountStringRefund amount.
paymentsIntegerIf the transaction has been deferred, the number of deferred installments. For example, 3.
authorizationTimeStringAuthorization time. RFC 3339 date format.
transactionidStringTransaction ID generated by Kushki.
authorizationStringTransaction authorization string. Approved refunds only.
creditcardStringLast 4 digits of the card's Primary Account Number.
cardtypeStringCard issuer. Possible values: VISA, MASTERCARD, CARNET, AMERICAN EXPRESS.
userIDIntegerID of the user who made the transaction.
urlStringUnique identifier to access a transaction ticket. Approved refunds only.
cardBrandStringCard Issuer Network.
cardCountryStringCard Country Code (ISO 3166-1 alpha-2).
cardClassStringDEBIT or CREDIT card.
launchTimeStringTime the request was sent.
maskedPANStringMasked card number.
uniqueReferenceStringUnique identifier per transaction generated on the client side to avoid duplicates. For example, a UUID.
transactionTypeStringTransaction type. Possible values: devolucion for refunds.
transactionRefundedIdStringOriginal refunded transaction ID.

Approved refund example#

{
    "cardBrand": "VISA",
    "cardCountry": "US",
    "cardClass": "CREDIT",
    "uniqueReference": "d6732f94-6cf2-4dfb-aed7-11b64b739407",
    "launchTime": "2024-08-16T10:02:37.965-0600",
    "userID": 61000,
    "authorizationTime": "2024-08-16T10:02:37.965-0600",
    "result": "aprobada",
    "amount": "1018.0",
    "payments": 0,
    "transactionid": "128013",
    "authorization": "BP4160",
    "creditcard": "0002",
    "cardtype": "VISA",
    "url": "19c6f19bc1a7a00a1d76021aa5eaef2627aba950",
    "maskedPAN": "400000******0002",
    "transactionType": "devolucion",
    "transactionRefundedId": "128012"
}

Rejected refund example#

{
    "cardBrand": "VISA",
    "cardCountry": "US",
    "cardClass": "CREDIT",
    "launchTime": "2024-08-15T16:22:52.461-0600",
    "userID": 61000,
    "authorizationTime": "2024-08-15T16:22:52.461-0600",
    "result": "rechazadaProsa",
    "amount": "1003.0",
    "payments": 0,
    "transactionid": "128015",
    "creditcard": "0002",
    "cardtype": "VISA",
    "maskedPAN": "400000******0002",
    "transactionType": "devolucion",
    "transactionRefundedId": "128014"
}

Got a suggestion on this documentation? Contact us.
Modified at 2026-08-25 17:39:41
Previous
API Keys
Next
Webhooks — Transfer Funds to Your Bank Account
Built with