ShopBack · AsyncAPI Specification
Shopback Payment Notification Webhooks
Version
View Spec
View on GitHub
CompanyPaymentsCashbackRewardsLoyaltyE-CommerceBuy Now Pay LaterPoint-of-SaleCheckoutSingaporeAsyncAPIEvents
AsyncAPI Specification
generated: '2026-08-02'
method: searched
source: >-
https://docs.shopback.com/docs/server-to-server-payment-notification-payment-notification-webhook +
https://docs.shopback.com/reference/key-concepts +
https://docs.shopback.com/reference/notification-1
spec_type: Webhooks
asyncapi_published: false
asyncapi_note: >-
ShopBack publishes no AsyncAPI document, no event catalog and no streaming
surface. Its only asynchronous surface is a merchant-implemented HTTP callback,
captured here as a webhook catalog. Nothing was fabricated into AsyncAPI form.
delivery:
style: merchant-implemented HTTP endpoint (ShopBack POSTs to it)
transport: HTTPS
method: POST
content_type: application/json
subscription: >-
The callback URL is supplied per order — as callbackUrl on the Online
Payments order/initiate and tokenized-payment charge/capture requests, and as
the webhookUrl configured during in-store partner onboarding.
expected_response: HTTP 200, returned as fast as possible; process asynchronously.
retry: >-
A non-200 response is retried for up to 30 minutes. ShopBack warns that a
30-minute confirmation delay materially degrades the consumer experience.
duplicate_delivery: >-
The same notification may be delivered more than once — handle it
idempotently.
source_of_truth: >-
ShopBack instructs merchants to treat the synchronous API response, not the
webhook, as the source of truth and never to block payment confirmation on
webhook delivery.
security:
signature_header: none published
verification_guidance: >-
ShopBack recommends cross-referencing order_uuid — which is returned only to
the merchant on order initiation — against the merchant's own record, since
order_context_token is a public value used in the redirect.
source_ip_allowlist:
- 52.77.77.186
- 18.139.142.64
- 54.169.195.114
- 52.77.135.75
- 18.140.220.149
- 13.228.6.43
- 54.254.76.7
- 52.64.93.144
- 13.55.37.110
events:
- name: payment.notification
api: ShopBack Online Payments API
trigger: >-
Sent immediately after a payment is confirmed by ShopBack Pay, and after a
tokenized-payment capture or immediate charge completes PSP processing.
docs: https://docs.shopback.com/docs/server-to-server-payment-notification-payment-notification-webhook
payload:
order_status:
type: string
values: [SUCCESS, ERROR]
note: The tokenized-payments docs describe the same field as SUCCESS or FAILED.
order_uuid:
type: string
description: ShopBack order identifier, also returned by order/initiate and by
the capture/charge response. Private to the merchant — use it to verify
the callback.
order_context_token:
type: string
description: Token identifying the order during the ShopBack Pay checkout
flow. Public — used in the redirect.
cart_id:
type: string
description: Merchant cart identifier submitted on order/initiate. Always null
for tokenized payments.
webhook_url:
type: string
description: Echoes the callbackUrl supplied by the merchant. Only present
when order_status is SUCCESS.
failure_code:
type: string
description: Internal failure code. Only present when order_status is ERROR.
known_values:
- ORDER_NOT_SUBMITTED
- HOOLAHJS_CLOSED
payment_type:
type: string
values: [PAY, PAYLATER]
description: Consumer payment type; documented as not live yet, populated for
completed and refunded orders only.
example: |
{
"cart_id": "34b5ds36-b24d-ds34-ds31-ds45dd563124",
"order_context_token": "d88fd4aa-2556-11eb-adc1-0242ac120002",
"order_status": "SUCCESS",
"order_uuid": "a5fd004a-2555-11eb-adc1-0242ac120002"
}
- name: instore.order.notification
api: ShopBack In-Store Payments API
trigger: >-
ShopBack POSTs the in-store order outcome to the webhookUrl the payment
partner supplied during onboarding. Modelled in the In-Store Payments API
OpenAPI as the merchant-implemented POST /<webhookUrl> operation
(operationId "Notification").
docs: https://docs.shopback.com/reference/notification-1
spec: openapi/shopback-in-store-payments-openapi.yml#/paths/~1%3CwebhookUrl%3E
implemented_by: the payment partner / merchant, not ShopBack
gaps:
- No AsyncAPI document, event registry or event-schema catalog is published.
- No webhook signature (HMAC or JWS) is provided for callback authenticity; the
documented mitigation is a shared-secret-free order_uuid cross-check plus an
IP allowlist.
- No webhook replay, event-log or delivery-status API is published.
Work with this as data
Every AsyncAPI spec here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for asyncapi
4 MCP tools reach this
find_asyncapisBrowse and filter every AsyncAPI spec in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This AsyncAPI spec
curl "https://apis.io/api/v1/asyncapis/shopback-payment-notification-webhooks"
All asyncapi
curl "https://apis.io/api/v1/asyncapis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.