Authentication
x-hallify-signature: <HALLIFY_SIGNATURE>HMAC-SHA256 signature credential. Each operation documents its exact protocol through x-hallify-hmac metadata and the operation description.
Parameters
providerKeyPath · RequiredStable payment-provider key selecting the webhook verification profile for this delivery.
stringFull definition
{ "example": "simulator", "type": "string" }x-hallify-timestampHeader · Requiredrfc3339 timestamp; accepted clock skew is ±300 seconds.
stringFull definition
{ "type": "string", "example": "example" }
Request body
Required
Payment attempt and provider event identifiers, provider status and occurrence time, plus optional external and masked-card metadata consumed as the signed payment event.
application/json
Full definition
{
"$ref": "#/components/schemas/PaymentProviderWebhookDto"
}Responses
200Returns whether the signed provider event was applied or recognized as an idempotent replay.
Full definition
{
"$ref": "#/components/schemas/PaymentProviderWebhookResultDto"
}{
"attemptId": "ebc45c68-e765-435d-8f7f-7ef875ce04bf",
"status": "PENDING",
"revision": 1,
"duplicate": true
}400Provider key or payment webhook payload is invalid
Full definition
{
"$ref": "#/components/schemas/TranslatedErrorDto"
}{
"statusCode": 400,
"error": "errors:http.badRequest",
"code": "HTTP_BAD_REQUEST",
"message": "errors:http.badRequest",
"translationKey": "errors:http.badRequest"
}401Payment webhook is unavailable or its HMAC signature is invalid or stale
Full definition
{
"$ref": "#/components/schemas/TranslatedErrorDto"
}{
"statusCode": 401,
"error": "errors:http.unauthorized",
"code": "HTTP_UNAUTHORIZED",
"message": "errors:http.unauthorized",
"translationKey": "errors:http.unauthorized"
}404Payment attempt was not found
Full definition
{
"$ref": "#/components/schemas/TranslatedErrorDto"
}{
"statusCode": 404,
"error": "errors:http.notFound",
"code": "HTTP_NOT_FOUND",
"message": "errors:http.notFound",
"translationKey": "errors:http.notFound"
}409Provider event identifier was reused with a different payload
Full definition
{
"$ref": "#/components/schemas/TranslatedErrorDto"
}{
"statusCode": 409,
"error": "errors:http.conflict",
"code": "HTTP_CONFLICT",
"message": "errors:http.conflict",
"translationKey": "errors:http.conflict"
}Schemas
PaymentProviderWebhookDto
Signed payment-provider event payload after HMAC verification at the provider webhook boundary.
attemptIdRequiredHallify UUID identifying attempt associated with payment provider webhook.
string · uuidFull definition
{ "type": "string", "format": "uuid", "description": "Hallify UUID identifying attempt associated with payment provider webhook.", "example": "ebc45c68-e765-435d-8f7f-7ef875ce04bf" }eventIdRequiredOpaque identifier for event associated with payment provider webhook; clients must not assume UUID syntax. Accepted values enforce maximum length 191.
stringFull definition
{ "type": "string", "maxLength": 191, "description": "Opaque identifier for event associated with payment provider webhook; clients must not assume UUID syntax. Accepted values enforce maximum length 191.", "example": "example-id" }statusRequiredCurrent lifecycle status of payment provider webhook; allowed values are AUTHORIZED, CAPTURED, DECLINED, FAILED, CANCELED.
stringFull definition
{ "type": "string", "enum": [ "AUTHORIZED", "CAPTURED", "DECLINED", "FAILED", "CANCELED" ], "description": "Current lifecycle status of payment provider webhook; allowed values are AUTHORIZED, CAPTURED, DECLINED, FAILED, CANCELED.", "example": "AUTHORIZED" }occurredAtRequiredRFC 3339 timestamp for occurred at; offsets represent the same absolute instant.
string · date-timeFull definition
{ "type": "string", "format": "date-time", "description": "RFC 3339 timestamp for occurred at; offsets represent the same absolute instant.", "example": "2026-01-15T12:00:00.000Z" }externalReferenceOptionalReference assigned by an external system and retained for reconciliation with payment provider webhook. Accepted values enforce maximum length 128.
stringFull definition
{ "type": "string", "maxLength": 128, "description": "Reference assigned by an external system and retained for reconciliation with payment provider webhook. Accepted values enforce maximum length 128.", "example": "example-reference" }cardBrandOptionalCard brand for payment provider webhook. Accepted values enforce maximum length 32.
stringFull definition
{ "type": "string", "maxLength": 32, "description": "Card brand for payment provider webhook. Accepted values enforce maximum length 32.", "example": "example" }cardLast4OptionalCard last4 for payment provider webhook.
stringFull definition
{ "type": "string", "pattern": "^\\d{4}$", "description": "Card last4 for payment provider webhook.", "example": "0001" }
Full definition
{
"type": "object",
"properties": {
"attemptId": {
"type": "string",
"format": "uuid",
"description": "Hallify UUID identifying attempt associated with payment provider webhook.",
"example": "ebc45c68-e765-435d-8f7f-7ef875ce04bf"
},
"eventId": {
"type": "string",
"maxLength": 191,
"description": "Opaque identifier for event associated with payment provider webhook; clients must not assume UUID syntax. Accepted values enforce maximum length 191.",
"example": "example-id"
},
"status": {
"type": "string",
"enum": [
"AUTHORIZED",
"CAPTURED",
"DECLINED",
"FAILED",
"CANCELED"
],
"description": "Current lifecycle status of payment provider webhook; allowed values are AUTHORIZED, CAPTURED, DECLINED, FAILED, CANCELED.",
"example": "AUTHORIZED"
},
"occurredAt": {
"type": "string",
"format": "date-time",
"description": "RFC 3339 timestamp for occurred at; offsets represent the same absolute instant.",
"example": "2026-01-15T12:00:00.000Z"
},
"externalReference": {
"type": "string",
"maxLength": 128,
"description": "Reference assigned by an external system and retained for reconciliation with payment provider webhook. Accepted values enforce maximum length 128.",
"example": "example-reference"
},
"cardBrand": {
"type": "string",
"maxLength": 32,
"description": "Card brand for payment provider webhook. Accepted values enforce maximum length 32.",
"example": "example"
},
"cardLast4": {
"type": "string",
"pattern": "^\\d{4}$",
"description": "Card last4 for payment provider webhook.",
"example": "0001"
}
},
"required": [
"attemptId",
"eventId",
"status",
"occurredAt"
],
"description": "Signed payment-provider event payload after HMAC verification at the provider webhook boundary.",
"example": {
"attemptId": "fc6f0fa9-b807-43e6-87b6-56edb271fb3f",
"eventId": "evt_01JHALLIFYEXAMPLE",
"status": "CAPTURED",
"occurredAt": "2026-08-11T10:30:00.000Z",
"externalReference": "provider-payment-1842",
"cardBrand": "visa",
"cardLast4": "4242"
}
}PaymentProviderWebhookResultDto
Returns whether the signed provider event was applied or recognized as an idempotent replay.
attemptIdRequiredHallify UUID identifying attempt associated with payment provider webhook.
string · uuidFull definition
{ "type": "string", "format": "uuid", "description": "Hallify UUID identifying attempt associated with payment provider webhook.", "example": "ebc45c68-e765-435d-8f7f-7ef875ce04bf" }statusRequiredCurrent lifecycle status of payment provider webhook; allowed values are PENDING, APPROVED, FAILED, CANCELED, CREATED, REQUIRES_ACTION, AUTHORIZED, CAPTURED, DECLINED, OFFLINE_ACCEPTED, RECONCILIATION_REQUIRED.
stringFull definition
{ "type": "string", "enum": [ "PENDING", "APPROVED", "FAILED", "CANCELED", "CREATED", "REQUIRES_ACTION", "AUTHORIZED", "CAPTURED", "DECLINED", "OFFLINE_ACCEPTED", "RECONCILIATION_REQUIRED" ], "description": "Current lifecycle status of payment provider webhook; allowed values are PENDING, APPROVED, FAILED, CANCELED, CREATED, REQUIRES_ACTION, AUTHORIZED, CAPTURED, DECLINED, OFFLINE_ACCEPTED, RECONCILIATION_REQUIRED.", "example": "PENDING" }revisionRequiredMonotonic optimistic-concurrency revision for payment provider webhook.
integerFull definition
{ "type": "integer", "description": "Monotonic optimistic-concurrency revision for payment provider webhook.", "example": 1 }duplicateRequiredWhether the submitted event was already accepted and handled as a duplicate.
booleanFull definition
{ "type": "boolean", "description": "Whether the submitted event was already accepted and handled as a duplicate.", "example": true }
Full definition
{
"type": "object",
"properties": {
"attemptId": {
"type": "string",
"format": "uuid",
"description": "Hallify UUID identifying attempt associated with payment provider webhook.",
"example": "ebc45c68-e765-435d-8f7f-7ef875ce04bf"
},
"status": {
"type": "string",
"enum": [
"PENDING",
"APPROVED",
"FAILED",
"CANCELED",
"CREATED",
"REQUIRES_ACTION",
"AUTHORIZED",
"CAPTURED",
"DECLINED",
"OFFLINE_ACCEPTED",
"RECONCILIATION_REQUIRED"
],
"description": "Current lifecycle status of payment provider webhook; allowed values are PENDING, APPROVED, FAILED, CANCELED, CREATED, REQUIRES_ACTION, AUTHORIZED, CAPTURED, DECLINED, OFFLINE_ACCEPTED, RECONCILIATION_REQUIRED.",
"example": "PENDING"
},
"revision": {
"type": "integer",
"description": "Monotonic optimistic-concurrency revision for payment provider webhook.",
"example": 1
},
"duplicate": {
"type": "boolean",
"description": "Whether the submitted event was already accepted and handled as a duplicate.",
"example": true
}
},
"required": [
"attemptId",
"status",
"revision",
"duplicate"
],
"description": "Returns whether the signed provider event was applied or recognized as an idempotent replay.",
"example": {
"attemptId": "ebc45c68-e765-435d-8f7f-7ef875ce04bf",
"status": "PENDING",
"revision": 1,
"duplicate": true
}
}TranslatedErrorDto
Stable error envelope emitted by the global HTTP exception boundary. Domain-specific machine data, when present, is nested under details.
statusCodeRequiredHTTP status code repeated from the response.
integerFull definition
{ "type": "integer", "description": "HTTP status code repeated from the response.", "example": 400 }errorRequiredTranslation key for the HTTP category, such as errors:http.conflict. The specific cause is identified by code and translationKey.
stringFull definition
{ "type": "string", "description": "Translation key for the HTTP category, such as errors:http.conflict. The specific cause is identified by code and translationKey.", "example": "errors.request.invalid" }codeRequiredStable machine-readable domain code, or an HTTP_* fallback when no domain code is provided. Branch on this field and the HTTP status; localized wording never controls retries or business decisions.
stringFull definition
{ "type": "string", "example": "HTTP_BAD_REQUEST", "description": "Stable machine-readable domain code, or an HTTP_* fallback when no domain code is provided. Branch on this field and the HTTP status; localized wording never controls retries or business decisions." }messageRequiredTranslation key, identical to translationKey. The API does not return localized display text. Resolve the key and translationValues in the consuming application.
stringFull definition
{ "type": "string", "example": "errors:http.badRequest", "description": "Translation key, identical to translationKey. The API does not return localized display text. Resolve the key and translationValues in the consuming application." }translationKeyRequiredCanonical translation key, identical to message. Status-specific errors:http.* keys cover unspecified failures. Public keys and EN/RU explanations are listed in Developers; unknown keys require a localized client fallback.
stringFull definition
{ "type": "string", "example": "errors:http.badRequest", "description": "Canonical translation key, identical to message. Status-specific errors:http.* keys cover unspecified failures. Public keys and EN/RU explanations are listed in Developers; unknown keys require a localized client fallback." }translationValuesOptionalOptional scalar values for placeholders in the translation. Treat values as data, escape them when rendering, and never use them as translation options.
objectFull definition
{ "type": "object", "additionalProperties": { "oneOf": [ { "type": "string", "example": "example" }, { "type": "number", "example": 0 }, { "type": "boolean", "example": true } ], "example": "example" }, "description": "Optional scalar values for placeholders in the translation. Treat values as data, escape them when rendering, and never use them as translation options.", "example": { "exampleKey": "example" } }validationErrorsOptionalField validation failures with translation keys and stable validator codes. Submitted values and raw validator text are not included.
arrayFull definition
{ "description": "Field validation failures with translation keys and stable validator codes. Submitted values and raw validator text are not included.", "type": "array", "items": { "$ref": "#/components/schemas/ValidationErrorDto" }, "example": [ { "field": "email", "translationKey": "validation:isEmail", "code": "isEmail", "message": "validation:isEmail" } ] }detailsOptionalOptional domain-specific blocker or validation details
oneOfFull definition
{ "description": "Optional domain-specific blocker or validation details", "oneOf": [ { "type": "array", "items": { "$ref": "#/components/schemas/JsonValue" }, "example": [ "example" ] }, { "type": "object", "additionalProperties": { "$ref": "#/components/schemas/JsonValue" }, "example": { "exampleKey": "example" } } ], "example": [ "example" ] }
Full definition
{
"type": "object",
"properties": {
"statusCode": {
"type": "integer",
"description": "HTTP status code repeated from the response.",
"example": 400
},
"error": {
"type": "string",
"description": "Translation key for the HTTP category, such as errors:http.conflict. The specific cause is identified by code and translationKey.",
"example": "errors.request.invalid"
},
"code": {
"type": "string",
"example": "HTTP_BAD_REQUEST",
"description": "Stable machine-readable domain code, or an HTTP_* fallback when no domain code is provided. Branch on this field and the HTTP status; localized wording never controls retries or business decisions."
},
"message": {
"type": "string",
"example": "errors:http.badRequest",
"description": "Translation key, identical to translationKey. The API does not return localized display text. Resolve the key and translationValues in the consuming application."
},
"translationKey": {
"type": "string",
"example": "errors:http.badRequest",
"description": "Canonical translation key, identical to message. Status-specific errors:http.* keys cover unspecified failures. Public keys and EN/RU explanations are listed in Developers; unknown keys require a localized client fallback."
},
"translationValues": {
"type": "object",
"additionalProperties": {
"oneOf": [
{
"type": "string",
"example": "example"
},
{
"type": "number",
"example": 0
},
{
"type": "boolean",
"example": true
}
],
"example": "example"
},
"description": "Optional scalar values for placeholders in the translation. Treat values as data, escape them when rendering, and never use them as translation options.",
"example": {
"exampleKey": "example"
}
},
"validationErrors": {
"description": "Field validation failures with translation keys and stable validator codes. Submitted values and raw validator text are not included.",
"type": "array",
"items": {
"$ref": "#/components/schemas/ValidationErrorDto"
},
"example": [
{
"field": "email",
"translationKey": "validation:isEmail",
"code": "isEmail",
"message": "validation:isEmail"
}
]
},
"details": {
"description": "Optional domain-specific blocker or validation details",
"oneOf": [
{
"type": "array",
"items": {
"$ref": "#/components/schemas/JsonValue"
},
"example": [
"example"
]
},
{
"type": "object",
"additionalProperties": {
"$ref": "#/components/schemas/JsonValue"
},
"example": {
"exampleKey": "example"
}
}
],
"example": [
"example"
]
}
},
"required": [
"statusCode",
"error",
"code",
"message",
"translationKey"
],
"description": "Stable error envelope emitted by the global HTTP exception boundary. Domain-specific machine data, when present, is nested under details.",
"example": {
"statusCode": 400,
"error": "errors:http.badRequest",
"code": "HTTP_BAD_REQUEST",
"message": "errors:http.badRequest",
"translationKey": "errors:http.badRequest"
}
}ValidationErrorDto
Field validation failure with a field path, stable validator code and a translation key. Human-readable text belongs to the consuming application.
fieldRequiredPublic field path. Nested properties and array indices are separated by dots.
stringFull definition
{ "type": "string", "example": "email", "description": "Public field path. Nested properties and array indices are separated by dots." }translationKeyRequiredTranslation key for this validator, identical to message. Resolve it using a client dictionary; see the public Developers error catalog.
stringFull definition
{ "type": "string", "example": "validation:isEmail", "description": "Translation key for this validator, identical to message. Resolve it using a client dictionary; see the public Developers error catalog." }codeRequiredStable validator identifier for this field failure. Custom validators may define additional identifiers.
stringFull definition
{ "type": "string", "example": "isEmail", "description": "Stable validator identifier for this field failure. Custom validators may define additional identifiers." }messageRequiredTranslation key describing this field validation failure, identical to translationKey. Submitted values and validator prose are not included.
stringFull definition
{ "type": "string", "example": "validation:isEmail", "description": "Translation key describing this field validation failure, identical to translationKey. Submitted values and validator prose are not included." }translationValuesOptionalOptional scalar values for placeholders in the translation. Treat values as data, escape them when rendering, and never use them as translation options.
objectFull definition
{ "type": "object", "additionalProperties": { "oneOf": [ { "type": "string", "example": "example" }, { "type": "number", "example": 0 }, { "type": "boolean", "example": true } ], "example": "example" }, "description": "Optional scalar values for placeholders in the translation. Treat values as data, escape them when rendering, and never use them as translation options.", "example": { "exampleKey": "example" } }
Full definition
{
"type": "object",
"properties": {
"field": {
"type": "string",
"example": "email",
"description": "Public field path. Nested properties and array indices are separated by dots."
},
"translationKey": {
"type": "string",
"example": "validation:isEmail",
"description": "Translation key for this validator, identical to message. Resolve it using a client dictionary; see the public Developers error catalog."
},
"code": {
"type": "string",
"example": "isEmail",
"description": "Stable validator identifier for this field failure. Custom validators may define additional identifiers."
},
"message": {
"type": "string",
"example": "validation:isEmail",
"description": "Translation key describing this field validation failure, identical to translationKey. Submitted values and validator prose are not included."
},
"translationValues": {
"type": "object",
"additionalProperties": {
"oneOf": [
{
"type": "string",
"example": "example"
},
{
"type": "number",
"example": 0
},
{
"type": "boolean",
"example": true
}
],
"example": "example"
},
"description": "Optional scalar values for placeholders in the translation. Treat values as data, escape them when rendering, and never use them as translation options.",
"example": {
"exampleKey": "example"
}
}
},
"required": [
"field",
"translationKey",
"code",
"message"
],
"description": "Field validation failure with a field path, stable validator code and a translation key. Human-readable text belongs to the consuming application.",
"example": {
"field": "email",
"translationKey": "validation:isEmail",
"code": "isEmail",
"message": "validation:isEmail"
}
}JsonValue
Recursively JSON-safe value used only where the owning contract intentionally allows free-form structured data.
Full definition
{
"oneOf": [
{
"type": "string",
"nullable": true,
"example": "example"
},
{
"type": "number",
"example": 0
},
{
"type": "boolean",
"example": true
},
{
"type": "array",
"items": {
"$ref": "#/components/schemas/JsonValue"
},
"example": [
"example"
]
},
{
"type": "object",
"additionalProperties": {
"$ref": "#/components/schemas/JsonValue"
},
"example": {
"exampleKey": "example"
}
}
],
"description": "Recursively JSON-safe value used only where the owning contract intentionally allows free-form structured data.",
"example": "example"
}