Payment
Webhook
Get a POST request on your server with the payment's details when its status changes.
POST → your webhook URLSet a webhook_url when you call Create Payment. Paybob then sends a POST request with a JSON body to that URL with the payment's details: the same fields that Verify Payment returns.
Use the webhook as a signal, not as proof. Take the pp_id from the body and call Verify Payment with your API key before you deliver the order, so a forged request can't mark an order as paid.
Payload
pp_idstringThe payment's ID.
full_namestringCustomer's full name.
email_addressstringCustomer's email address.
mobile_numberstringCustomer's mobile number.
gatewaystringName of the payment method the customer used, e.g.
Bkash Personal.amountstringAmount charged, as a decimal string with 8 decimal places.
feestringFee added to the payment, as a decimal string.
discount_amountstringDiscount applied, as a decimal string.
net_totalnumberTotal after fee and discount, as a number.
currencystringCurrency code, upper case, e.g.
BDT.metadataobjectThe
metadatayou sent with Create Payment, returned unchanged.senderstringThe account the customer paid from, e.g. their wallet number.
transaction_idstringThe payment method's transaction ID.
statusstringPayment status, e.g.
refunded.datestringWhen the payment was made, e.g.
Sep 7, 2026 08:28 PM.
Handling a webhook
- Read the JSON body and take the
pp_id. - Call Verify Payment with that
pp_idand your API key. Use the payment it returns, not the webhook body. - Find your order, for example from
metadata.order_id, and check thatstatus,amountandcurrencymatch before you deliver it. - Make your handler safe to run twice for the same
pp_id: only update an order whose status actually changed.