{
"checkoutId": "<string>",
"items": [
{
"id": "<string>",
"productId": "<string>",
"productName": "<string>",
"fulfillments": [
{
"index": 123,
"status": "<string>",
"cardCode": "<string>",
"cardPin": "<string>",
"cardUrl": "<string>",
"vendorOrderId": "<string>",
"TxId": "<string>",
"errorMessage": "<string>",
"fulfilledAt": 1753142400000
}
]
}
],
"timestamp": 1753142400000
}Webhook payloads
B2B order callback
Legacy unsigned callback for B2B orders — includes card codes; see the guide before using it.
WEBHOOK
b2bOrderCallback
{
"checkoutId": "<string>",
"items": [
{
"id": "<string>",
"productId": "<string>",
"productName": "<string>",
"fulfillments": [
{
"index": 123,
"status": "<string>",
"cardCode": "<string>",
"cardPin": "<string>",
"cardUrl": "<string>",
"vendorOrderId": "<string>",
"TxId": "<string>",
"errorMessage": "<string>",
"fulfilledAt": 1753142400000
}
]
}
],
"timestamp": 1753142400000
}Authorizations
API key (wg_live_…) created in the dashboard (Account → API Keys).
Shown once at creation; only a hash is stored server-side.
Body
application/json
Legacy B2B order callback — UNSIGNED and fire-and-forget. Contains full fulfillment data INCLUDING card codes.
Response
200
Any response is ignored; delivery is fire-and-forget.