Curlec Partner Webhooks API

Configure webhooks for sub-merchant accounts to receive payment events. Maximum 30 per account.

OpenAPI Specification

curlec-partner-webhooks-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  title: Razorpay Bills Partner Webhooks API
  version: 1.0.0
  description: Razorpay payment gateway APIs for accepting payments, managing orders, processing refunds, payouts, and subscriptions. All amounts are in the smallest currency sub-unit (e.g. paise for INR). Supports 180+ payment methods including UPI, cards, netbanking, wallets, and EMI.
  termsOfService: https://razorpay.com/terms/
  contact:
    name: Razorpay Support
    url: https://razorpay.com/support/
    email: support@razorpay.com
  license:
    name: Proprietary
    url: https://razorpay.com/terms/
  x-logo:
    url: https://razorpay.com/favicon.png
  x-auth-environments:
    test:
      keyPrefix: rzp_test_
      description: Test mode — keys prefixed rzp_test_. Same API endpoint (https://api.razorpay.com/v1). No real money movement. Use test card numbers from https://razorpay.com/docs/payments/payments/test-card-details/.
    live:
      keyPrefix: rzp_live_
      description: Live mode — keys prefixed rzp_live_. Real money movement. Requires KYC and business activation on the Razorpay Dashboard.
servers:
- url: https://api.razorpay.com/v1
  description: Production
security:
- basicAuth: []
- oauth2:
  - read_only
tags:
- name: Partner Webhooks
  description: Configure webhooks for sub-merchant accounts to receive payment events. Maximum 30 per account.
paths:
  /v2/accounts/{account_id}/webhooks:
    post:
      operationId: createPartnerWebhook
      summary: Create a webhook for a sub-merchant
      description: 'Create a webhook to receive events for a sub-merchant account. Maximum 30 webhooks per account. Authentication: OAuth access_token.'
      tags:
      - Partner Webhooks
      security:
      - basicAuth: []
      parameters:
      - name: account_id
        in: path
        required: true
        schema:
          type: string
        description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`).
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - url
              - events
              properties:
                url:
                  type: string
                alert_email:
                  type: string
                secret:
                  type: string
                active:
                  type: boolean
                events:
                  type: object
                  additionalProperties:
                    type: boolean
      responses:
        '200':
          description: Webhook created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PartnerWebhook'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
    get:
      operationId: listPartnerWebhooks
      summary: List webhooks for a sub-merchant
      description: 'Retrieve all webhooks configured for a sub-merchant account. Authentication: OAuth access_token.'
      tags:
      - Partner Webhooks
      security:
      - basicAuth: []
      parameters:
      - name: account_id
        in: path
        required: true
        schema:
          type: string
        description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`).
      responses:
        '200':
          description: List of webhooks
          content:
            application/json:
              schema:
                type: object
                properties:
                  entity:
                    type: string
                  count:
                    type: integer
                  items:
                    type: array
                    items:
                      $ref: '#/components/schemas/PartnerWebhook'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
  /v2/accounts/{account_id}/webhooks/{webhook_id}:
    get:
      operationId: fetchPartnerWebhook
      summary: Fetch a webhook by ID
      description: 'Retrieve details of a specific webhook for a sub-merchant account. Authentication: OAuth access_token.'
      tags:
      - Partner Webhooks
      security:
      - basicAuth: []
      parameters:
      - name: account_id
        in: path
        required: true
        schema:
          type: string
        description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`).
      - name: webhook_id
        in: path
        required: true
        schema:
          type: string
        description: Unique identifier of the webhook (e.g. `we_00000000000001`).
      responses:
        '200':
          description: Webhook details
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PartnerWebhook'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        '404':
          $ref: '#/components/responses/404'
    patch:
      operationId: updatePartnerWebhook
      summary: Update a webhook
      description: 'Update webhook URL, events, secret, or active status for a sub-merchant account. Authentication: OAuth access_token.'
      tags:
      - Partner Webhooks
      security:
      - basicAuth: []
      parameters:
      - name: account_id
        in: path
        required: true
        schema:
          type: string
        description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`).
      - name: webhook_id
        in: path
        required: true
        schema:
          type: string
        description: Unique identifier of the webhook (e.g. `we_00000000000001`).
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PartnerWebhook'
      responses:
        '200':
          description: Webhook updated
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PartnerWebhook'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
    delete:
      operationId: deletePartnerWebhook
      summary: Delete a webhook
      description: 'Delete a webhook for a sub-merchant account. Returns empty array on success. Authentication: OAuth access_token.'
      tags:
      - Partner Webhooks
      security:
      - basicAuth: []
      parameters:
      - name: account_id
        in: path
        required: true
        schema:
          type: string
        description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`).
      - name: webhook_id
        in: path
        required: true
        schema:
          type: string
        description: Unique identifier of the webhook (e.g. `we_00000000000001`).
      responses:
        '200':
          description: Webhook deleted
          content:
            application/json:
              schema:
                type: object
                description: Empty object on success.
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '429':
          $ref: '#/components/responses/429'
        '500':
          $ref: '#/components/responses/500'
        '404':
          $ref: '#/components/responses/404'
components:
  responses:
    '404':
      description: Resource not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    '400':
      description: Bad request. Invalid parameters or missing required fields.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    '401':
      description: Authentication failed. Invalid or missing API key credentials.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    '500':
      description: Internal server error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    '429':
      description: Rate limit exceeded. Implement exponential backoff with jitter before retrying.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    PartnerWebhook:
      type: object
      description: A webhook configured for a sub-merchant account via the Partners API. Maximum 30 webhooks per account.
      properties:
        id:
          type: string
          description: Webhook ID, max 14 characters
        entity:
          type: string
          enum:
          - webhook
        owner_id:
          type: string
        owner_type:
          type: string
        url:
          type: string
          description: HTTPS URL to receive webhook events
        alert_email:
          type: string
        secret:
          type: string
          description: Shared secret for HMAC verification (write-only)
        secret_exists:
          type: boolean
        active:
          type: boolean
        events:
          type: object
          additionalProperties:
            type: boolean
          description: Map of event names to boolean
        service:
          type: string
        context:
          type: array
          items:
            type: string
        disabled_at:
          type: integer
        created_at:
          type: integer
        updated_at:
          type: integer
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: 'Error code. Examples: BAD_REQUEST_ERROR, GATEWAY_ERROR, SERVER_ERROR.'
            description:
              type: string
            source:
              type: string
              description: Where the error originated (e.g. business, gateway).
            step:
              type: string
            reason:
              type: string
              description: 'Machine-readable reason. Examples: insufficient_funds, invalid_expiry_date, declined_by_bank.'
            metadata:
              type: object
            field:
              type: string
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
      description: HTTP Basic authentication using your Razorpay API key pair. Use key_id as the username and key_secret as the password. Encode as Base64(key_id:key_secret). Keys are environment-scoped (Test vs Live). Obtain keys at https://dashboard.razorpay.com/app/keys. Keys are case-sensitive.
    oauth2:
      type: oauth2
      description: OAuth 2.0 via the Razorpay MCP server (mcp.razorpay.com). Supports Authorization Code with PKCE (S256) for user-delegated access and Client Credentials for server-to-server access. Tokens expire in 3600 seconds. Dynamic Client Registration available at the registration endpoint. For integration setup see https://razorpay.com/docs/build/llm-docs/mcp-server/oauth.md.
      flows:
        authorizationCode:
          authorizationUrl: https://mcp.razorpay.com/authorize
          tokenUrl: https://mcp.razorpay.com/token
          refreshUrl: https://mcp.razorpay.com/token
          scopes:
            read_only: Read-only access to Razorpay account data (payments, orders, refunds, payouts, subscriptions, invoices)
        clientCredentials:
          tokenUrl: https://mcp.razorpay.com/token
          scopes:
            read_only: Read-only access to Razorpay account data (payments, orders, refunds, payouts, subscriptions, invoices)
externalDocs:
  description: Razorpay API Documentation
  url: https://razorpay.com/docs/api/
x-tagGroups:
- name: Core Payments
  tags:
  - Orders
  - Payments
  - Refunds
  - Payment Downtimes
- name: Payment Collection
  tags:
  - Payment Links
  - QR Codes
- name: Billing & Subscriptions
  tags:
  - Items
  - Invoices
  - Plans
  - Subscriptions
- name: Customer Management
  tags:
  - Customers
  - Documents
- name: Finance & Reconciliation
  tags:
  - Settlements
  - Instant Settlements
  - Disputes
- name: Route & Marketplace
  tags:
  - Linked Accounts
  - Transfers
- name: Smart Collect
  tags:
  - Virtual Accounts
- name: Partners & Onboarding
  tags:
  - Partner Accounts
  - Partner Products
  - Partner Stakeholders
  - Partner Documents
  - Partner Webhooks
- name: Bills
  tags:
  - Bills
- name: RazorpayX
  tags:
  - X Contacts
  - X Fund Accounts
  - X Account Validation
  - X Banking Balances
  - X Payouts
  - X Payout Links
  - X Transactions
x-rateLimit:
  description: Razorpay does not publish specific rate limits. If you receive HTTP 429, implement exponential backoff with jitter and retry. Add randomisation to avoid thundering-herd effects.
  throttleStatus: 429
  strategy: exponential backoff with jitter
x-pagination:
  description: All list endpoints return at most 100 records per call (1000 for settlement recon). Use count and skip together to paginate. Date range filters (from/to) use Unix timestamps in seconds.
  example: GET /payments?from=1700000000&to=1700086400&count=100&skip=100
x-amountEncoding:
  description: 'All monetary amounts are in the smallest currency sub-unit. For INR: 1 rupee = 100 paise, so ₹500 = 50000. Minimum for INR is 100 paise (₹1). Three-decimal currencies (KWD, BHD, OMR): drop last decimal digit. Zero-decimal currencies (JPY): pass value as-is.'