---
title: NPP Credit Rejections Webhook
slug: api/npp-credit-rejections-webhook
docTags: 
createdAt: 2026-09-11T04:19:29.965Z
---

{
  "id": "pat-8p71fsLLqtdiCZS0P",
  "type": "api-oas-v2",
  "data": {
    "method": "POST",
    "url": "https://api.mpay.com.au/NPPCREDITREJECTIONSEVENTWEBHOOK_TARGET_URL",
    "servers": [
      {
        "url": "https://api.mpay.com.au/NPPCREDITREJECTIONSEVENTWEBHOOK_TARGET_URL",
        "description": "Production URL"
      },
      {
        "url": "https://api.m-pay.com.au/NPPCREDITREJECTIONSEVENTWEBHOOK_TARGET_URL",
        "description": "Sandbox URL"
      }
    ],
    "name": "NPP Credit Rejections Webhook",
    "description": "<p>When an NPP payment intended for an ABA account or PayID belonging to you is rejected because it matched no active reconciliation rule, Monoova sends a callback in the format below.</p>\n<p>To subscribe to this webhook use the Subscriptions APIs.</p>\n<p><strong>Event name:</strong> <code>NPPCreditRejections</code></p>",
    "contentType": "application/json",
    "request": {
      "pathParameters": [],
      "headerParameters": [
        {
          "kind": "optional",
          "name": "Authorisation",
          "type": "string",
          "example": "******",
          "description": "<p><strong>Optional</strong>. Shared secret that Monoova echoes back on every callback so your endpoint can authenticate the caller. The value is the one you registered on the subscription and is masked in this document. Omitted when no authorisation value was registered. Compare it in constant time and reject the notification with a 401 if it does not match.</p>",
          "default": "******",
          "pattern": "^[\\x20-\\x7E]{1,512}$"
        },
        {
          "kind": "optional",
          "name": "Verification-Signature",
          "type": "string",
          "example": "e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=",
          "description": "<p><strong>Optional</strong> in the schema, but sent by Monoova on every notification. A base64 encoded cryptographic signature used to verify both the integrity of the message and that Monoova is its source. The hashing method is SHA256 and the public key can be retrieved from <code>/public/v1/certificate/public-key</code>. Verify it before you act on the payload, and reject the notification with a 401 if verification fails.</p>",
          "default": "e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=",
          "pattern": "^[A-Za-z0-9+/]+={0,2}$"
        },
        {
          "kind": "optional",
          "name": "Webhookid",
          "type": "integer<int64>",
          "example": 1234567,
          "description": "<p><strong>Optional</strong>. Unique identifier for this webhook notification. Store it and treat a repeat of the same value as a redelivery of a notification you have already processed. Pattern: <code>^\\d{1,19}$</code>.</p>",
          "default": 1234567,
          "format": "int64"
        }
      ],
      "queryParameters": [],
      "bodyDataParameters": [
        {
          "kind": "required",
          "name": "body",
          "type": "array",
          "example": "[{\"id\":884231707,\"batchId\":20260910,\"dateTime\":\"2026-09-10T14:32:11\",\"transactionType\":\"NPP\",\"transactionCode\":\"50\",\"status\":\"Rejected\",\"reason\":\"No matching reconciliation rule\",\"amount\":150.75,\"bsb\":\"802-985\",\"accountNumber\":\"300000123\",\"accountName\":\"Acme Pty Ltd\",\"payId\":\"payments@acme.com.au\",\"payIdName\":\"ACME PAYMENTS\",\"lodgementRef\":\"ACME INV 10023\",\"endToEndId\":\"E2E-2026-0000123\",\"remitterName\":\"J SMITH\",\"sourceBsb\":\"062-000\",\"sourceAccountNumber\":\"12345678\",\"sourceAccountName\":\"JOHN A SMITH\",\"indicator\":\"W\",\"withholdingTaxAmount\":15.25,\"nameOfUserSupplyingFile\":\"ACME PTY LTD\",\"numberOfUserSupplyingFile\":\"123456\",\"descriptionOfEntriesOnFile\":\"PAYROLL\",\"ledgerAccountNumber\":\"4210000012345678\",\"ledgerUniqueReference\":\"ACME-LEDGER-0007\"}]",
          "description": "<p>A single inbound payment that Monoova could not allocate to one of your accounts. Shared by the <code>InboundDirectCreditRejections</code> and <code>NPPCreditRejections</code> events.</p>",
          "customType": "rejectedTransactionClass[]",
          "schema": [
            {
              "name": "id",
              "kind": "optional",
              "type": "integer<int32>",
              "description": "<p><strong>Required</strong>. Monoova generated unique identifier for the rejected transaction. Pattern: <code>^\\d{1,10}$</code>.</p>",
              "example": 884231707,
              "default": 884231707,
              "format": "int32"
            },
            {
              "name": "batchId",
              "kind": "optional",
              "type": "integer<int32>",
              "nullable": true,
              "description": "<p><strong>Conditional</strong>. Payment batch identifier. Populated for batched rails, where payments arrive in batches through the day, and null for real-time NPP payments that are not batched. Pattern: <code>^\\d{1,10}$</code>.</p>",
              "example": 20260910,
              "default": 20260910,
              "format": "int32"
            },
            {
              "name": "dateTime",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Date and time the transaction was received, in Sydney local time (AEST/AEDT).</p>",
              "example": "2026-09-10T14:32:11",
              "default": "2026-09-10T14:32:11",
              "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
            },
            {
              "name": "transactionType",
              "kind": "optional",
              "type": "string<DE | NPP>",
              "description": "<p><strong>Required</strong>. Rail the rejected payment arrived on. <code>DE</code> for Direct Entry and <code>NPP</code> for the New Payments Platform.</p>",
              "example": "NPP",
              "default": "NPP",
              "enum": [
                "DE",
                "NPP"
              ],
              "pattern": "^(DE|NPP)$"
            },
            {
              "name": "transactionCode",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Industry standard transaction code carried with the payment. <code>50</code> identifies an NPP credit.</p>",
              "example": "50",
              "default": "50",
              "pattern": "^\\d{2}$"
            },
            {
              "name": "status",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Status Monoova recorded against the transaction.</p>",
              "example": "Rejected",
              "default": "Rejected",
              "pattern": "^[A-Za-z ]{1,40}$"
            },
            {
              "name": "reason",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Reason the payment was rejected — typically that it matched no active reconciliation rule, or that the payer's account was not on your whitelist.</p>",
              "example": "No matching reconciliation rule",
              "default": "No matching reconciliation rule",
              "pattern": "^.{1,280}$"
            },
            {
              "name": "amount",
              "kind": "optional",
              "type": "number<double>",
              "nullable": true,
              "description": "<p><strong>Optional</strong>. Payment amount in AUD, to two decimal places for cents. Declared nullable in the source specification, so guard against a null. Pattern: <code>^\\d{1,13}(\\.\\d{1,2})?$</code>.</p>",
              "example": 150.75,
              "default": 150.75,
              "format": "double"
            },
            {
              "name": "bsb",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. BSB of the intended payee account. Six digits, with or without the conventional hyphen after the third digit.</p>",
              "example": "802-985",
              "default": "802-985",
              "pattern": "^\\d{3}-?\\d{3}$"
            },
            {
              "name": "accountNumber",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Payee bank account number the payment was addressed to.</p>",
              "example": "300000123",
              "default": "300000123",
              "pattern": "^\\d{5,10}$"
            },
            {
              "name": "accountName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Account name submitted with the payment. Note that the two source specifications describe this field differently — as the payer submitted name for <code>InboundDirectCreditRejections</code> and the payee submitted name for <code>NPPCreditRejections</code>. Confirm with Monoova before relying on it.</p>",
              "example": "Acme Pty Ltd",
              "default": "Acme Pty Ltd",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "payId",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned when the payment was addressed to a PayID. Holds the PayID value — an email address in the common case.</p>",
              "example": "payments@acme.com.au",
              "default": "payments@acme.com.au",
              "pattern": "^.{1,256}$"
            },
            {
              "name": "payIdName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned alongside <code>payId</code>. The name displayed to payers for that PayID.</p>",
              "example": "ACME PAYMENTS",
              "default": "ACME PAYMENTS",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "lodgementRef",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Reference submitted by the payer with the payment.</p>",
              "example": "ACME INV 10023",
              "default": "ACME INV 10023",
              "pattern": "^.{0,18}$"
            },
            {
              "name": "endToEndId",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Osko end-to-end identifier supplied by the payer and carried unchanged across the NPP. Echo it back on any related payment so the two legs can be matched.</p>",
              "example": "E2E-2026-0000123",
              "default": "E2E-2026-0000123",
              "pattern": "^[A-Za-z0-9\\/+?:().,'\\s-]{0,35}$"
            },
            {
              "name": "remitterName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Remitting entity as supplied with the payment.</p>",
              "example": "J SMITH",
              "default": "J SMITH",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "sourceBsb",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. BSB of the payer's account. Note that the two source specifications label this field differently — <code>Source BSB</code> for <code>InboundDirectCreditRejections</code> and <code>Payer BSB</code> for <code>NPPCreditRejections</code>.</p>",
              "example": "062-000",
              "default": "062-000",
              "pattern": "^\\d{3}-?\\d{3}$"
            },
            {
              "name": "sourceAccountNumber",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Payer's bank account number.</p>",
              "example": "12345678",
              "default": "12345678",
              "pattern": "^\\d{5,10}$"
            },
            {
              "name": "sourceAccountName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Populated for NPP transactions only, and holds the payer's bank account name. For Direct Entry transactions this field is not supplied — use <code>RemitterName</code> instead.</p>",
              "example": "JOHN A SMITH",
              "default": "JOHN A SMITH",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "indicator",
              "kind": "optional",
              "type": "string< | W | X | Y>",
              "description": "<p><strong>Conditional</strong>. Withholding tax indicator, returned only on payments that carry one. Blank where none applies; <code>W</code> for a dividend paid to a resident of a country with a double tax agreement in force; <code>X</code> for a dividend paid to a resident of any other country; <code>Y</code> for interest paid to a non-resident.</p>",
              "example": "W",
              "default": "W",
              "enum": [
                "",
                "W",
                "X",
                "Y"
              ],
              "pattern": "^[WXY]?$"
            },
            {
              "name": "withholdingTaxAmount",
              "kind": "optional",
              "type": "number<double>",
              "nullable": true,
              "description": "<p><strong>Conditional</strong>. Withholding tax deducted, returned only alongside a populated <code>indicator</code>. Blank or null where no withholding tax applies; otherwise an AUD amount to two decimal places for cents. Pattern: <code>^\\d{1,13}(\\.\\d{1,2})?$</code>.</p>",
              "example": 15.25,
              "default": 15.25,
              "format": "double"
            },
            {
              "name": "nameOfUserSupplyingFile",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Direct Entry only. Preferred name of the user that supplied the Direct Entry file. Not supplied on NPP transactions.</p>",
              "example": "ACME PTY LTD",
              "default": "ACME PTY LTD",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "numberOfUserSupplyingFile",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Direct Entry only. The User Identification Number assigned by APCA and the user's financial institution. Not supplied on NPP transactions.</p>",
              "example": "123456",
              "default": "123456",
              "pattern": "^\\d{0,6}$"
            },
            {
              "name": "descriptionOfEntriesOnFile",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Direct Entry only. Description of the entries carried on the Direct Entry file. Not supplied on NPP transactions.</p>",
              "example": "PAYROLL",
              "default": "PAYROLL",
              "pattern": "^.{0,12}$"
            },
            {
              "name": "ledgerAccountNumber",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned when the funds were allocated to a Monoova ledger account. Holds the 16-digit ledger account number that was credited. Absent when no ledger allocation applies.</p>",
              "example": "4210000012345678",
              "default": "4210000012345678",
              "pattern": "^\\d{16}$"
            },
            {
              "name": "ledgerUniqueReference",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned alongside <code>LedgerAccountNumber</code>. Your own unique reference registered against that ledger account, used to tie the credit back to your customer record.</p>",
              "example": "ACME-LEDGER-0007",
              "default": "ACME-LEDGER-0007",
              "pattern": "^.{1,64}$"
            }
          ],
          "modelRef": "#/components/schemas/rejectedTransactionClass",
          "isExpanded": true
        }
      ],
      "formDataParameters": [],
      "oAuthParameters": [],
      "cookieParameters": []
    },
    "responses": [
      {
        "statusCode": "200",
        "description": "<p><strong>Success.</strong> The notification passed validation and your endpoint has accepted responsibility for it. Return this as soon as the payload is persisted — do not wait for downstream processing. Monoova treats any 2xx as a successful delivery and will not retry.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"status\":\"Received\",\"webhookId\":1234567,\"receivedAt\":\"2026-09-10T14:32:12\"}",
            "description": "<p>Body your endpoint returns to acknowledge a notification. The body is optional — Monoova treats any 2xx status as a successful delivery — but returning it makes your acknowledgements easier to trace.</p>",
            "customType": "WebhookAcknowledgement",
            "schema": [
              {
                "name": "status",
                "kind": "optional",
                "type": "string<Received>",
                "description": "<p><strong>Required</strong>. Confirms the notification was accepted for processing. Return the literal value <code>Received</code>.</p>",
                "example": "Received",
                "default": "Received",
                "enum": [
                  "Received"
                ],
                "pattern": "^Received$"
              },
              {
                "name": "webhookId",
                "kind": "optional",
                "type": "integer<int64>",
                "description": "<p><strong>Optional</strong>. Echo of the <code>Webhookid</code> request header, so the acknowledgement can be matched to Monoova's delivery log. Pattern: <code>^\\d{1,19}$</code>.</p>",
                "example": 1234567,
                "default": 1234567,
                "format": "int64"
              },
              {
                "name": "receivedAt",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Optional</strong>. Date and time your endpoint accepted the notification, in ISO 8601 format.</p>",
                "example": "2026-09-10T14:32:12",
                "default": "2026-09-10T14:32:12",
                "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
              }
            ],
            "modelRef": "#/components/schemas/WebhookAcknowledgement",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "400",
        "description": "<p><strong>Bad Request.</strong> The notification could not be parsed, or a field failed your validation. Monoova will not retry a notification that is rejected with a 400, so return it only for a genuinely malformed payload — never for a transient fault on your side.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"status\":\"Rejected\",\"errorCode\":\"INVALID_PAYLOAD\",\"errorMessage\":\"Field 'Amount' is not a valid decimal value.\",\"webhookId\":1234567,\"receivedAt\":\"2026-09-10T14:32:12\"}",
            "description": "<p>Body your endpoint returns when a notification cannot be accepted. Returned with a 400, 401 or 500 status.</p>",
            "customType": "WebhookErrorResponse",
            "schema": [
              {
                "name": "status",
                "kind": "optional",
                "type": "string<Rejected | Unauthorised | Error>",
                "description": "<p><strong>Required</strong>. Processing outcome. Return <code>Rejected</code> with a 400, <code>Unauthorised</code> with a 401 and <code>Error</code> with a 500.</p>",
                "example": "Rejected",
                "default": "Rejected",
                "enum": [
                  "Rejected",
                  "Unauthorised",
                  "Error"
                ],
                "pattern": "^(Rejected|Unauthorised|Error)$"
              },
              {
                "name": "errorCode",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Machine-readable code identifying the failure, in upper snake case. Keep the value stable so Monoova support can group repeated failures.</p>",
                "example": "INVALID_PAYLOAD",
                "default": "INVALID_PAYLOAD",
                "pattern": "^[A-Z][A-Z0-9_]{2,49}$"
              },
              {
                "name": "errorMessage",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Human-readable explanation of the failure. Do not include payment data or credentials in this field.</p>",
                "example": "Field 'Amount' is not a valid decimal value.",
                "default": "Field 'Amount' is not a valid decimal value.",
                "pattern": "^.{1,500}$"
              },
              {
                "name": "webhookId",
                "kind": "optional",
                "type": "integer<int64>",
                "description": "<p><strong>Optional</strong>. Echo of the <code>Webhookid</code> request header, so the failure can be matched to Monoova's delivery log. Pattern: <code>^\\d{1,19}$</code>.</p>",
                "example": 1234567,
                "default": 1234567,
                "format": "int64"
              },
              {
                "name": "receivedAt",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Optional</strong>. Date and time your endpoint received the notification, in ISO 8601 format.</p>",
                "example": "2026-09-10T14:32:12",
                "default": "2026-09-10T14:32:12",
                "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
              }
            ],
            "modelRef": "#/components/schemas/WebhookErrorResponse",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "401",
        "description": "<p><strong>Unauthorised.</strong> The <code>Authorisation</code> header was missing or did not match the value registered on the subscription, or the <code>Verification-Signature</code> header failed SHA256 verification against the Monoova public key. Return this without processing the payload.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"status\":\"Unauthorised\",\"errorCode\":\"SIGNATURE_VERIFICATION_FAILED\",\"errorMessage\":\"Verification-Signature did not match the Monoova public key.\",\"webhookId\":1234567,\"receivedAt\":\"2026-09-10T14:32:12\"}",
            "description": "<p>Body your endpoint returns when a notification cannot be accepted. Returned with a 400, 401 or 500 status.</p>",
            "customType": "WebhookErrorResponse",
            "schema": [
              {
                "name": "status",
                "kind": "optional",
                "type": "string<Rejected | Unauthorised | Error>",
                "description": "<p><strong>Required</strong>. Processing outcome. Return <code>Rejected</code> with a 400, <code>Unauthorised</code> with a 401 and <code>Error</code> with a 500.</p>",
                "example": "Rejected",
                "default": "Rejected",
                "enum": [
                  "Rejected",
                  "Unauthorised",
                  "Error"
                ],
                "pattern": "^(Rejected|Unauthorised|Error)$"
              },
              {
                "name": "errorCode",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Machine-readable code identifying the failure, in upper snake case. Keep the value stable so Monoova support can group repeated failures.</p>",
                "example": "INVALID_PAYLOAD",
                "default": "INVALID_PAYLOAD",
                "pattern": "^[A-Z][A-Z0-9_]{2,49}$"
              },
              {
                "name": "errorMessage",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Human-readable explanation of the failure. Do not include payment data or credentials in this field.</p>",
                "example": "Field 'Amount' is not a valid decimal value.",
                "default": "Field 'Amount' is not a valid decimal value.",
                "pattern": "^.{1,500}$"
              },
              {
                "name": "webhookId",
                "kind": "optional",
                "type": "integer<int64>",
                "description": "<p><strong>Optional</strong>. Echo of the <code>Webhookid</code> request header, so the failure can be matched to Monoova's delivery log. Pattern: <code>^\\d{1,19}$</code>.</p>",
                "example": 1234567,
                "default": 1234567,
                "format": "int64"
              },
              {
                "name": "receivedAt",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Optional</strong>. Date and time your endpoint received the notification, in ISO 8601 format.</p>",
                "example": "2026-09-10T14:32:12",
                "default": "2026-09-10T14:32:12",
                "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
              }
            ],
            "modelRef": "#/components/schemas/WebhookErrorResponse",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "500",
        "description": "<p><strong>Internal Server Error.</strong> Your endpoint accepted the notification but could not process it because of a fault on your side. Monoova retries a notification that fails with a 5xx, so return this — rather than a 400 — whenever the failure is transient and a redelivery could succeed.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"status\":\"Error\",\"errorCode\":\"DOWNSTREAM_UNAVAILABLE\",\"errorMessage\":\"Ledger service unavailable; retry delivery.\",\"webhookId\":1234567,\"receivedAt\":\"2026-09-10T14:32:12\"}",
            "description": "<p>Body your endpoint returns when a notification cannot be accepted. Returned with a 400, 401 or 500 status.</p>",
            "customType": "WebhookErrorResponse",
            "schema": [
              {
                "name": "status",
                "kind": "optional",
                "type": "string<Rejected | Unauthorised | Error>",
                "description": "<p><strong>Required</strong>. Processing outcome. Return <code>Rejected</code> with a 400, <code>Unauthorised</code> with a 401 and <code>Error</code> with a 500.</p>",
                "example": "Rejected",
                "default": "Rejected",
                "enum": [
                  "Rejected",
                  "Unauthorised",
                  "Error"
                ],
                "pattern": "^(Rejected|Unauthorised|Error)$"
              },
              {
                "name": "errorCode",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Machine-readable code identifying the failure, in upper snake case. Keep the value stable so Monoova support can group repeated failures.</p>",
                "example": "INVALID_PAYLOAD",
                "default": "INVALID_PAYLOAD",
                "pattern": "^[A-Z][A-Z0-9_]{2,49}$"
              },
              {
                "name": "errorMessage",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Human-readable explanation of the failure. Do not include payment data or credentials in this field.</p>",
                "example": "Field 'Amount' is not a valid decimal value.",
                "default": "Field 'Amount' is not a valid decimal value.",
                "pattern": "^.{1,500}$"
              },
              {
                "name": "webhookId",
                "kind": "optional",
                "type": "integer<int64>",
                "description": "<p><strong>Optional</strong>. Echo of the <code>Webhookid</code> request header, so the failure can be matched to Monoova's delivery log. Pattern: <code>^\\d{1,19}$</code>.</p>",
                "example": 1234567,
                "default": 1234567,
                "format": "int64"
              },
              {
                "name": "receivedAt",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Optional</strong>. Date and time your endpoint received the notification, in ISO 8601 format.</p>",
                "example": "2026-09-10T14:32:12",
                "default": "2026-09-10T14:32:12",
                "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
              }
            ],
            "modelRef": "#/components/schemas/WebhookErrorResponse",
            "isExpanded": true
          }
        ]
      }
    ],
    "hasXCodeSamples": false,
    "examples": {
      "languages": [
        {
          "id": "VuP94S2uVw4wjhAyG3dJO",
          "language": "curl",
          "label": "cURL",
          "code": "curl --request POST \\\n     --url https://api.mpay.com.au/NPPCREDITREJECTIONSEVENTWEBHOOK_TARGET_URL \\\n     --header 'accept: application/json' \\\n     --header 'content-type: application/json' \\\n     --header 'authorisation: ******' \\\n     --header 'verification-signature: e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=' \\\n     --header 'webhookid: 1234567' \\\n     --data-raw '[\n     {\n     \"id\": 884231707,\n     \"batchId\": 20260910,\n     \"dateTime\": \"2026-09-10T14:32:11\",\n     \"transactionType\": \"NPP\",\n     \"transactionCode\": \"50\",\n     \"status\": \"Rejected\",\n     \"reason\": \"No matching reconciliation rule\",\n     \"amount\": 150.75,\n     \"bsb\": \"802-985\",\n     \"accountNumber\": \"300000123\",\n     \"accountName\": \"Acme Pty Ltd\",\n     \"payId\": \"payments@acme.com.au\",\n     \"payIdName\": \"ACME PAYMENTS\",\n     \"lodgementRef\": \"ACME INV 10023\",\n     \"endToEndId\": \"E2E-2026-0000123\",\n     \"remitterName\": \"J SMITH\",\n     \"sourceBsb\": \"062-000\",\n     \"sourceAccountNumber\": \"12345678\",\n     \"sourceAccountName\": \"JOHN A SMITH\",\n     \"indicator\": \"W\",\n     \"withholdingTaxAmount\": 15.25,\n     \"nameOfUserSupplyingFile\": \"ACME PTY LTD\",\n     \"numberOfUserSupplyingFile\": \"123456\",\n     \"descriptionOfEntriesOnFile\": \"PAYROLL\",\n     \"ledgerAccountNumber\": \"4210000012345678\",\n     \"ledgerUniqueReference\": \"ACME-LEDGER-0007\"\n     }\n     ]'"
        },
        {
          "id": "zQvNGxeFM133c2vZAqBvW",
          "language": "javascript",
          "label": "javascript",
          "code": "var myHeaders = new Headers();\nmyHeaders.append(\"accept\", \"application/json\");\nmyHeaders.append(\"content-type\", \"application/json\");\nmyHeaders.append(\"authorisation\", \"******\");\nmyHeaders.append(\"verification-signature\", \"e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=\");\nmyHeaders.append(\"webhookid\", \"1234567\");\n\nvar raw = JSON.stringify([\n   {\n      \"id\": 884231707,\n      \"batchId\": 20260910,\n      \"dateTime\": \"2026-09-10T14:32:11\",\n      \"transactionType\": \"NPP\",\n      \"transactionCode\": \"50\",\n      \"status\": \"Rejected\",\n      \"reason\": \"No matching reconciliation rule\",\n      \"amount\": 150.75,\n      \"bsb\": \"802-985\",\n      \"accountNumber\": \"300000123\",\n      \"accountName\": \"Acme Pty Ltd\",\n      \"payId\": \"payments@acme.com.au\",\n      \"payIdName\": \"ACME PAYMENTS\",\n      \"lodgementRef\": \"ACME INV 10023\",\n      \"endToEndId\": \"E2E-2026-0000123\",\n      \"remitterName\": \"J SMITH\",\n      \"sourceBsb\": \"062-000\",\n      \"sourceAccountNumber\": \"12345678\",\n      \"sourceAccountName\": \"JOHN A SMITH\",\n      \"indicator\": \"W\",\n      \"withholdingTaxAmount\": 15.25,\n      \"nameOfUserSupplyingFile\": \"ACME PTY LTD\",\n      \"numberOfUserSupplyingFile\": \"123456\",\n      \"descriptionOfEntriesOnFile\": \"PAYROLL\",\n      \"ledgerAccountNumber\": \"4210000012345678\",\n      \"ledgerUniqueReference\": \"ACME-LEDGER-0007\"\n   }\n]);\n\nvar requestOptions = {\n   method: 'POST',\n   headers: myHeaders,\n   body: raw,\n   redirect: 'follow'\n};\n\nfetch(\"https://api.mpay.com.au/NPPCREDITREJECTIONSEVENTWEBHOOK_TARGET_URL\", requestOptions)\n   .then(response => response.text())\n   .then(result => console.log(result))\n   .catch(error => console.log('error', error));"
        },
        {
          "id": "04I39xfmPmta9ncudvzkR",
          "language": "ruby",
          "label": "Ruby",
          "code": "require \"uri\"\nrequire \"json\"\nrequire \"net/http\"\n\nurl = URI(\"https://api.mpay.com.au/NPPCREDITREJECTIONSEVENTWEBHOOK_TARGET_URL\")\n\nhttps = Net::HTTP.new(url.host, url.port)\nhttps.use_ssl = true\n\nrequest = Net::HTTP::Post.new(url)\nrequest[\"accept\"] = \"application/json\"\nrequest[\"content-type\"] = \"application/json\"\nrequest[\"authorisation\"] = \"******\"\nrequest[\"verification-signature\"] = \"e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=\"\nrequest[\"webhookid\"] = \"1234567\"\nrequest.body = JSON.dump([\n   {\n      \"id\": 884231707,\n      \"batchId\": 20260910,\n      \"dateTime\": \"2026-09-10T14:32:11\",\n      \"transactionType\": \"NPP\",\n      \"transactionCode\": \"50\",\n      \"status\": \"Rejected\",\n      \"reason\": \"No matching reconciliation rule\",\n      \"amount\": 150.75,\n      \"bsb\": \"802-985\",\n      \"accountNumber\": \"300000123\",\n      \"accountName\": \"Acme Pty Ltd\",\n      \"payId\": \"payments@acme.com.au\",\n      \"payIdName\": \"ACME PAYMENTS\",\n      \"lodgementRef\": \"ACME INV 10023\",\n      \"endToEndId\": \"E2E-2026-0000123\",\n      \"remitterName\": \"J SMITH\",\n      \"sourceBsb\": \"062-000\",\n      \"sourceAccountNumber\": \"12345678\",\n      \"sourceAccountName\": \"JOHN A SMITH\",\n      \"indicator\": \"W\",\n      \"withholdingTaxAmount\": 15.25,\n      \"nameOfUserSupplyingFile\": \"ACME PTY LTD\",\n      \"numberOfUserSupplyingFile\": \"123456\",\n      \"descriptionOfEntriesOnFile\": \"PAYROLL\",\n      \"ledgerAccountNumber\": \"4210000012345678\",\n      \"ledgerUniqueReference\": \"ACME-LEDGER-0007\"\n   }\n])\n\nresponse = https.request(request)\nputs response.read_body\n"
        },
        {
          "id": "SpeoDA8dKksQktr4qQ4PK",
          "language": "python",
          "label": "Python",
          "code": "import requests\nimport json\n\nurl = \"https://api.mpay.com.au/NPPCREDITREJECTIONSEVENTWEBHOOK_TARGET_URL\"\n\npayload = json.dumps([\n   {\n      \"id\": 884231707,\n      \"batchId\": 20260910,\n      \"dateTime\": \"2026-09-10T14:32:11\",\n      \"transactionType\": \"NPP\",\n      \"transactionCode\": \"50\",\n      \"status\": \"Rejected\",\n      \"reason\": \"No matching reconciliation rule\",\n      \"amount\": 150.75,\n      \"bsb\": \"802-985\",\n      \"accountNumber\": \"300000123\",\n      \"accountName\": \"Acme Pty Ltd\",\n      \"payId\": \"payments@acme.com.au\",\n      \"payIdName\": \"ACME PAYMENTS\",\n      \"lodgementRef\": \"ACME INV 10023\",\n      \"endToEndId\": \"E2E-2026-0000123\",\n      \"remitterName\": \"J SMITH\",\n      \"sourceBsb\": \"062-000\",\n      \"sourceAccountNumber\": \"12345678\",\n      \"sourceAccountName\": \"JOHN A SMITH\",\n      \"indicator\": \"W\",\n      \"withholdingTaxAmount\": 15.25,\n      \"nameOfUserSupplyingFile\": \"ACME PTY LTD\",\n      \"numberOfUserSupplyingFile\": \"123456\",\n      \"descriptionOfEntriesOnFile\": \"PAYROLL\",\n      \"ledgerAccountNumber\": \"4210000012345678\",\n      \"ledgerUniqueReference\": \"ACME-LEDGER-0007\"\n   }\n])\nheaders = {\n   'accept': 'application/json',\n   'content-type': 'application/json',\n   'authorisation': '******',\n   'verification-signature': 'e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=',\n   'webhookid': '1234567'\n}\n\nresponse = requests.request(\"POST\", url, headers=headers, data=payload)\n\nprint(response.text)\n"
        }
      ],
      "selectedLanguageId": "VuP94S2uVw4wjhAyG3dJO"
    },
    "results": {
      "languages": [
        {
          "id": "ca_F5N6doVzRBM-Ww2C9o",
          "language": "200",
          "code": "// Success. The notification passed validation and your endpoint has accepted responsibility for it. Return this as soon as the payload is persisted — do not wait for downstream processing. Monoova treats any 2xx as a successful delivery and will not retry.\n{\n  \"status\": \"Received\",\n  \"webhookId\": 1234567,\n  \"receivedAt\": \"2026-09-10T14:32:12\"\n}"
        },
        {
          "id": "hg_C22EpbPdTp3yDbkZ2s",
          "language": "400",
          "code": "// Bad Request. The notification could not be parsed, or a field failed your validation. Monoova will not retry a notification that is rejected with a 400, so return it only for a genuinely malformed payload — never for a transient fault on your side.\n{\n  \"status\": \"Rejected\",\n  \"errorCode\": \"INVALID_PAYLOAD\",\n  \"errorMessage\": \"Field 'Amount' is not a valid decimal value.\",\n  \"webhookId\": 1234567,\n  \"receivedAt\": \"2026-09-10T14:32:12\"\n}"
        },
        {
          "id": "iaZUf2LUT-PeXoDxP8rKI",
          "language": "401",
          "code": "// Unauthorised. The Authorisation header was missing or did not match the value registered on the subscription, or the Verification-Signature header failed SHA256 verification against the Monoova public key. Return this without processing the payload.\n{\n  \"status\": \"Rejected\",\n  \"errorCode\": \"INVALID_PAYLOAD\",\n  \"errorMessage\": \"Field 'Amount' is not a valid decimal value.\",\n  \"webhookId\": 1234567,\n  \"receivedAt\": \"2026-09-10T14:32:12\"\n}"
        },
        {
          "id": "6sC4oNTIMtDs9HP-N4mK5",
          "language": "500",
          "code": "// Internal Server Error. Your endpoint accepted the notification but could not process it because of a fault on your side. Monoova retries a notification that fails with a 5xx, so return this — rather than a 400 — whenever the failure is transient and a redelivery could succeed.\n{\n  \"status\": \"Rejected\",\n  \"errorCode\": \"INVALID_PAYLOAD\",\n  \"errorMessage\": \"Field 'Amount' is not a valid decimal value.\",\n  \"webhookId\": 1234567,\n  \"receivedAt\": \"2026-09-10T14:32:12\"\n}"
        }
      ],
      "selectedLanguageId": "ca_F5N6doVzRBM-Ww2C9o"
    }
  },
  "children": [
    {
      "text": ""
    }
  ]
}