POST
/webhooks/outbound/card.3ds.otpcard.3ds.otp
This operation documents an outbound webhook request that CryptoCard Platform sends to your configured webhook URL. Sent when a card 3DS OTP is received from the card platform. Configure the destination URL and webhook secret on the company configuration. We send an HTTP `POST` with `Content-Type: application/json` and `X-Hoppacard-Signature`. The signature is a lowercase hex HMAC-SHA256 digest of the exact request body, using your webhook secret as the key. Return any 2xx status code to acknowledge the webhook.
Authentication
Send your API key in the x-api-key header on every request.
Parameters
| Field | Type | Required | Description |
|---|---|---|---|
| X-Hoppacard-Signature (header) | string | Yes | Lowercase hex HMAC-SHA256 signature of the raw request body, generated with your webhook secret. |
Request body
application/json
| Field | Type | Required | Description |
|---|---|---|---|
| id | string | Yes | Unique webhook event id. |
| type | card.3ds.otp | Yes | Webhook event type. |
| domain | card | Yes | Business domain for the event. |
| provider | hoppacard | Yes | Provider that originated the event. |
| timestamp | string (date-time) | Yes | UTC time when the webhook was created. |
| data | object | Yes | Event-specific payload for `card.3ds.otp`. |
Responses
200 — Return any 2xx response to acknowledge receipt.
Example request
curl -X POST "https://{base_url}/webhooks/outbound/card.3ds.otp" \
-H "x-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"id":"…","type":"…","domain":"…","provider":"…"}'This page is generated from the live OpenAPI specification and always matches the current API.