Receive Npp Payment Status Webhook
POST
https://api.mpay.com.au/NPPPAYMENTSTATUSEVENTWEBHOOK_TARGET_URL
Authorisationstring<p><strong>Optional</strong>. Shared secret that Monoova echoes back on every callback so your endpoint can authenticate the caller. The value is the one you registered on the subscription and is masked in this document. Omitted when no authorisation value was registered. Compare it in constant time and reject the notification with a 401 if it does not match.</p>
Verification-Signaturestring<p><strong>Optional</strong> in the schema, but sent by Monoova on every notification. A base64 encoded cryptographic signature used to verify both the integrity of the message and that Monoova is its source. The hashing method is SHA256 and the public key can be retrieved from <code>/public/v1/certificate/public-key</code>. Verify it before you act on the payload, and reject the notification with a 401 if verification fails.</p>
Webhookidinteger<int64><p><strong>Optional</strong>. Unique identifier for this webhook notification. Store it and treat a repeat of the same value as a redelivery of a notification you have already processed. Pattern: <code>^\d{1,19}$</code>.</p>
bodyobject<p>Payload sent when the status of a pending outbound NPP payment changes. Sent for the <code>NppPaymentStatus</code> event. The <code>Pending</code> status itself is never reported by this webhook.</p>
200<p><strong>Success.</strong> The notification passed validation and your endpoint has accepted responsibility for it. Return this as soon as the payload is persisted — do not wait for downstream processing. Monoova treats any 2xx as a successful delivery and will not retry.</p>
400<p><strong>Bad Request.</strong> The notification could not be parsed, or a field failed your validation. Monoova will not retry a notification that is rejected with a 400, so return it only for a genuinely malformed payload — never for a transient fault on your side.</p>
401<p><strong>Unauthorised.</strong> The <code>Authorisation</code> header was missing or did not match the value registered on the subscription, or the <code>Verification-Signature</code> header failed SHA256 verification against the Monoova public key. Return this without processing the payload.</p>
500<p><strong>Internal Server Error.</strong> Your endpoint accepted the notification but could not process it because of a fault on your side. Monoova retries a notification that fails with a 5xx, so return this — rather than a 400 — whenever the failure is transient and a redelivery could succeed.</p>
curl --request POST \
--url https://api.mpay.com.au/NPPPAYMENTSTATUSEVENTWEBHOOK_TARGET_URL \
--header 'accept: application/json' \
--header 'content-type: application/json' \
--header 'authorisation: ******' \
--header 'verification-signature: e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=' \
--header 'webhookid: 1234567' \
--data-raw '{
"TransactionId": "884231703",
"UniqueReference": "ACME-PAY-000123",
"TransactionDate": "2026-09-10",
"Amount": "150.00",
"Status": "Successful",
"AccountNumber": "12345678",
"AccountName": "John A Smith",
"Bsb": "802-985",
"PayId": "[email protected]",
"PayIdType": "Email",
"EndToEndId": "E2E-2026-0000123",
"LodgementReference": "ACME INV 10023",
"RemitterName": "ACME PTY LTD",
"RejectionDateTime": "2026-09-10T14:35:02",
"RejectionReasonDescription": "Account closed",
"RejectionTransactionId": "884231704"
}'