reseller
POST /v1/reseller/webhooks/{code}/{orgId}
Ingest a signed callback from a reseller's OWN payment gateway.
Аутентификација
Ова крајња тачка је јавна. Не захтева никакве акредитиве нити организацију — то је оно што читају наш сопствени маркетиншки сајт и машине за одговоре са вештачком интелигенцијом.
Где се уноси ID ваше организације
Ова крајња тачка узима ID ваше организације у самом URL-у, као orgId. Замените га у путањи — не постоји заглавље или параметар упита који могу послужити уместо тога.
Идентификатор ваше организације се налази на екрану са API кључевима на вашој контролној табли, поред самог кључа. То је исти идентификатор у сваком позиву који упутите.
Испробајте
Замените све што је у угластим заградама сопственим вредностима, а чувар места кључа кључем са своје контролне табле.
curl -X POST https://api.zinndigital.com/v1/reseller/webhooks/{code}/{orgId}Пријављени сте? API конзола на вашој контролној табли попуњава ваш прави id организације и ваш сопствени кључ, и покреће захтев према живом API-ју како бисте могли да видите стварни одговор. Отворите ову крајњу тачку у API конзоли
Детаљи
Unauthenticated by design, exactly like the platform callbacks above — the provider's signature over the raw body is the authentication. What differs is whose secret it is verified against: this endpoint resolves the reseller's own credential from Vault first, because /v1/webhooks/{code} verifies against Zinn®'s secret and answers 400 INVALID_SIGNATURE to anything a reseller's account sends it. Without this endpoint a BYO gateway can charge but never settle asynchronously — no SCA completion, no mandate confirmation, no crypto IPN. ⛔ A valid signature is not an authorization to touch a tenant. It proves only that the delivery came from the account we hold keys for; the event may act only on organizations that bill back to this reseller, and anything else is acknowledged with 200 and changes nothing. Replays are expected and converge on a dedupe key namespaced per reseller, so two accounts delivering the same provider event id cannot silently cancel each other out.
Параметри
| Назив | Тип | Обавезно | Шта је ово |
|---|---|---|---|
code (path) | string | Да | The gateway code — stripe, paypal or nowpayments. |
orgId (path) | Uuid | Да | The RESELLER organization whose own gateway account is calling back. It is in the path because the signing secret is per organization: the engine must resolve their credential… |
Одговор
| Назив | Тип | Обавезно | Шта је ово |
|---|---|---|---|
status | string<handled, ignored, duplicate> | Да | handled — acted on. ignored — a valid event of a type Zinn® does not consume. duplicate — already processed; Stripe may stop redelivering. |
Грешке које ова крајња тачка може вратити
400 · 404 · 503