payment.pending
A payment is initiated, awaiting provider confirmation.
When this fires
A subscriber initiates checkout and is redirected to the provider, but the charge is not yet confirmed (bank transfer, crypto settlement, hosted-checkout sessions).
PayPal carries neither session_id nor order_id: a PayPal payment.pending gives you only provider, plan_id, and subscriber_id, so it cannot be correlated to a specific checkout attempt. Absent keys are omitted entirely rather than sent as null; the one exception is Stripe's session_id, which is always present on the Stripe path but may be null.
Caveats
- A pending payment is not yet a subscription.
subscription_idis intentionally absent. - The same checkout may emit one
payment.pendingfollowed by eitherpayment.succeededorpayment.failed. Correlate onsession_idororder_idwhere the provider supplies one; for PayPal, fall back tosubscriber_idplusplan_id. - Subscribers who close the provider page without completing will not produce a final outcome event; pending sessions can hang indefinitely.
Related events
payment.succeeded,payment.failed: terminal outcomes.subscription.activated: fires alongside thepayment.succeededthat completes a first checkout.
Ability to subscribe
A token needs this to subscribe an endpoint to the event.
Header Parameters
t=<unix seconds>,v1=<hex>: the HMAC-SHA256 of "<t>.<raw body>" under the endpoint's secret. Verify it before acting, and refuse a t more than 300 seconds from now. During a secret rotation a v0= signature under the previous secret may precede v1=.
The event's ULID, bare. The envelope's id is the same ULID prefixed evt_, so strip the prefix before comparing. Deduplicate on it: a retry carries the same id.
The event name, the same as the envelope's type.
Always application/json.
Always Subscriby-Webhooks/1.0.
Payload
JSONWhat Subscriby posts to your endpointapplication/json
The signed JSON envelope posted to your endpoint.
The envelope every event is delivered in.
Responses
2XXAny success status
Your endpoint acknowledged the delivery. Any 2xx status within 30 seconds marks it delivered; the response body is ignored.
defaultAny other status
Any other status, a connection failure, or no answer within 30 seconds counts as a failed attempt. The delivery is retried 8 times, after 10 seconds, 30 seconds, 2 minutes, 10 minutes, 1 hour, 6 hours, 1 day, 3 days; the last failure dead-letters it, and it can be retried from the dashboard or POST /v1/webhook-deliveries/{delivery}/retry. After 20 consecutive failures the endpoint is paused until it is resumed.
How is this guide?
Last updated on