Skip to main content
This page covers the practices that keep your webhook endpoint secure and your Fintoc integration reliable. These practices include filtering the events you listen to, handling duplicate deliveries, and verifying that events come from Fintoc.

Types of events

Configure your endpoint to listen only to the events your application needs. Ignoring the rest avoids extra load on your server.

Avoid event duplication

Fintoc can send the same event more than once, for example after a delivery retry. Make your endpoint idempotent so a repeated event causes no duplicate work. Store the id of each event after you process it, then discard any event whose id you have already stored.

Security

Securing your endpoints protects your customers’ information. Fintoc gives you two ways to confirm events come from Fintoc.

Receive events with an HTTPS server

Your webhook endpoint must serve HTTPS with a valid TLS certificate. Fintoc does not send events to an endpoint without one.

Verify events are sent from Fintoc

Verify webhook signatures to confirm events come from Fintoc. Additionally, make sure these events originate from one of the following IP addresses: