Setup
Configure your webhook URL via the Update Platform Settings endpoint:webhookUrl to null to disable webhooks.
Payload format
All webhook payloads follow the same structure:Event types
Transfers
Entities
Accounts
IBANs
Responding to webhooks
Your endpoint should return a200 status code within 10 seconds. If Otim does not receive a 200 response, the webhook will be retried up to 5 times with exponential backoff.
Verifying signatures
Each webhook request includes aX-Otim-Signature header containing an HMAC-SHA256 signature of the request body. Verify this signature to ensure the request came from Otim.