webhookUrl is signed with your account’s webhook secret. Verifying the signature confirms the request actually came from Pagoramp and wasn’t forged or replayed.
Headers
Each webhook request includes two headers:X-Pagoramp-Signature: a hex-encoded HMAC-SHA256 signature of the request.X-Pagoramp-Timestamp: the Unix timestamp (seconds) the request was signed at.
Getting your webhook secret
Generate or view your webhook secret in the merchant dashboard under Settings > Webhooks. It’s shown once at generation time - store it securely. You can regenerate it at any time (this invalidates the previous secret).Signature construction
raw_request_body is the exact, unparsed JSON body of the request - verify against the raw bytes, not a re-serialized version of the parsed object (re-serializing can change key ordering or whitespace and break the signature).

