Payology sends POST to the HTTPS receiver configured for your organization. Authentication/custom headers depend on that configuration; there is no universal signature header in the reviewed sender. Acknowledge durable receipt with any 2xx; the body is receiver-defined and may be empty. Delivery may be repeated: deduplicate by webhook_token and business identifiers. Network failures, 408, 429 and 5xx are retryable; other HTTP errors are terminal except for one configured OAuth token refresh on 401/403. Retry count, delay and HTTP timeout are configurable and were not checked in a live environment.
Receiver acknowledgement
After durably accepting the event, the receiver may return:
HTTP/1.1 204 No ContentAn empty HTTP 200 is also accepted. A response JSON body is optional and defined by the receiver.
Returns delivery headers include event-type: Returns, payment-method-type: ACH/PAD/X9, payment-token, mobile-payment and reference-id when available. ACH notices of change (C##) do not produce Returns webhook events in the current return producer.
200Receiver accepted the event. Response body is optional and defined by the receiver.
204Receiver accepted the event with no response body.
408Receiver timeout; delivery is retryable.
429Receiver rate limit; delivery is retryable.
2XXAny successful 2xx response acknowledges delivery.
4XXOther receiver errors generally end this delivery. Configured OAuth may refresh once after 401 or 403.
5XXReceiver server error; delivery is retryable.