Appearance
Catalog SDK Webhooks
Catalog SDK webhooks notify your backend when a hosted Catalog SDK order reaches a final fulfillment outcome.
Setup
Set up your backend webhook URL for Catalog SDK order updates in the IIMMPACT dashboard.
IIMMPACT sends a POST request to your webhook URL when the order reaches a final outcome. Supported event types are:
| Event | Sent when |
|---|---|
order.completed | The order finishes fulfillment. |
order.timeout | The order times out before payment is confirmed with IIMMPACT. One timeout event is generated, with status set to timeout; delivery may repeat during retries. |
order.timeout uses the same payload shape and signature as order.completed.
Webhook requests include this signature header:
http
X-Webhook-Signature: sha256=<hex hmac sha256 of raw request body>Verify the signature with your Catalog SDK webhook secret before processing the event.
Sample Payload
The values below are an illustrative example.
json
{
"type": "order.completed",
"order_id": 12345,
"user_id": "customer-123",
"total_amount": "25.00",
"refund_amount": "5.00",
"status": "completed",
"payment_reference": "client-payment-ref-123",
"completed_at": "2026-05-05T10:05:00.000Z",
"items": [
{
"product_code": "D10",
"account_number": "60123456789",
"amount": "10.00",
"quantity": 2,
"extras": {
"foo": "bar"
},
"transactions": [
{
"refid": "sdk-abc-1",
"status": "successful",
"status_code": 20,
"sn": "SN-123",
"pin": "PIN-123",
"expiry": "20290309",
"voucherlink": "https://example.com/voucher",
"remarks": "Success"
},
{
"refid": "sdk-abc-2",
"status": "failed",
"status_code": 52,
"sn": "",
"pin": "",
"expiry": "",
"voucherlink": "",
"remarks": "Invalid Account No"
}
]
}
]
}Timeout Example
No payment was confirmed with IIMMPACT before timeout, so payment_reference is null and the order has no fulfillment transactions (illustrative example). This does not prove that your payment provider never charged the customer. Reconcile the payment in your system before closing the order.
json
{
"type": "order.timeout",
"order_id": 12346,
"user_id": "customer-123",
"total_amount": "20.00",
"refund_amount": "0.00",
"status": "timeout",
"payment_reference": null,
"completed_at": "2026-05-05T10:30:00.000Z",
"items": [
{
"product_code": "D10",
"account_number": "60123456789",
"amount": "10.00",
"quantity": 2,
"transactions": []
}
]
}Response And Retries
Respond with any 2xx status after your backend accepts the webhook. IIMMPACT retries network errors, 408, 429 and 5xx responses; other 4xx responses are treated as terminal delivery failures.
Webhook URLs must use https and resolve to public addresses. Redirects are not followed, and requests time out after 30 seconds.
