---
title: Receive Payment Webhook
slug: api/receive-payment-webhook
docTags: 
createdAt: 2026-09-11T04:19:29.965Z
---

{
  "id": "upcZ9jGIpOkQY7d701b1-",
  "type": "api-oas-v2",
  "data": {
    "method": "POST",
    "url": "https://api.mpay.com.au/NPPRECEIVEPAYMENTEVENTWEBHOOK_TARGET_URL",
    "servers": [
      {
        "url": "https://api.mpay.com.au/NPPRECEIVEPAYMENTEVENTWEBHOOK_TARGET_URL",
        "description": "Production URL"
      },
      {
        "url": "https://api.m-pay.com.au/NPPRECEIVEPAYMENTEVENTWEBHOOK_TARGET_URL",
        "description": "Sandbox URL"
      }
    ],
    "name": "Receive Payment Webhook",
    "description": "<p>When an NPP payment is received, Monoova sends a callback in the format below.</p>\n<p>To subscribe to this webhook use the Subscriptions APIs.</p>\n<p><strong>Event name:</strong> <code>NPPReceivePayment</code></p>",
    "contentType": "application/json",
    "request": {
      "pathParameters": [],
      "headerParameters": [
        {
          "kind": "optional",
          "name": "Authorisation",
          "type": "string",
          "example": "******",
          "description": "<p><strong>Optional</strong>. Shared secret that Monoova echoes back on every callback so your endpoint can authenticate the caller. The value is the one you registered on the subscription and is masked in this document. Omitted when no authorisation value was registered. Compare it in constant time and reject the notification with a 401 if it does not match.</p>",
          "default": "******",
          "pattern": "^[\\x20-\\x7E]{1,512}$"
        },
        {
          "kind": "optional",
          "name": "Verification-Signature",
          "type": "string",
          "example": "e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=",
          "description": "<p><strong>Optional</strong> in the schema, but sent by Monoova on every notification. A base64 encoded cryptographic signature used to verify both the integrity of the message and that Monoova is its source. The hashing method is SHA256 and the public key can be retrieved from <code>/public/v1/certificate/public-key</code>. Verify it before you act on the payload, and reject the notification with a 401 if verification fails.</p>",
          "default": "e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=",
          "pattern": "^[A-Za-z0-9+/]+={0,2}$"
        },
        {
          "kind": "optional",
          "name": "Webhookid",
          "type": "integer<int64>",
          "example": 1234567,
          "description": "<p><strong>Optional</strong>. Unique identifier for this webhook notification. Store it and treat a repeat of the same value as a redelivery of a notification you have already processed. Pattern: <code>^\\d{1,19}$</code>.</p>",
          "default": 1234567,
          "format": "int64"
        }
      ],
      "queryParameters": [],
      "bodyDataParameters": [
        {
          "kind": "required",
          "name": "body",
          "type": "object",
          "example": "{\"TransactionId\":\"884231701\",\"DateTime\":\"2026-09-10T14:32:11\",\"Amount\":\"150.00\",\"AccountNumber\":\"300000123\",\"AccountName\":\"Acme Pty Ltd\",\"Bsb\":\"802-985\",\"PayId\":\"payments@acme.com.au\",\"PayIdName\":\"ACME PAYMENTS\",\"RemitterName\":\"J SMITH\",\"SourceBsb\":\"062-000\",\"SourceAccountNumber\":\"12345678\",\"SourceAccountName\":\"JOHN A SMITH\",\"PaymentDescription\":\"Invoice 10023\",\"EndToEndId\":\"E2E-2026-0000123\",\"CreditorReferenceInformation\":\"RF18539007547034\",\"ReconciliationRuleReference\":\"RULE-ACME-001\",\"CategoryPurposeCode\":\"SALA\",\"UltimateCreditorName\":\"Acme Holdings Pty Ltd\",\"USINumber\":\"12345678901SPN\",\"USICreditorScheme\":\"USI\",\"LedgerAccountNumber\":\"4210000012345678\",\"LedgerUniqueReference\":\"ACME-LEDGER-0007\",\"ReceiptNumber\":8842317,\"RefundDetails\":{\"InboundAmount\":\"150.00\",\"RefundAmount\":\"150.00\",\"RefundId\":\"991122334\"}}",
          "description": "<p>Payload of a single NPP payment received into one of your accounts. Sent for the <code>NPPReceivePayment</code> event.</p>",
          "customType": "WebhookNppReceivePaymentNotification",
          "schema": [
            {
              "name": "TransactionId",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Monoova's unique identifier for the received payment. Use it as the idempotency key when you record the transaction, so a redelivered notification is not double-counted.</p>",
              "example": "884231701",
              "default": "884231701",
              "pattern": "^\\d{1,19}$"
            },
            {
              "name": "DateTime",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Date and time Monoova received the payment, in Sydney local time (AEST/AEDT).</p>",
              "example": "2026-09-10T14:32:11",
              "default": "2026-09-10T14:32:11",
              "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
            },
            {
              "name": "Amount",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Value of the payment in AUD, expressed as a decimal string with exactly two decimal places for cents. Never negative.</p>",
              "example": "150.00",
              "default": "150.00",
              "pattern": "^\\d{1,13}\\.\\d{2}$"
            },
            {
              "name": "AccountNumber",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. Bank account number the payment was credited to — your AutoMatcher receivable account or mAccount.</p>",
              "example": "300000123",
              "default": "300000123",
              "pattern": "^\\d{5,10}$"
            },
            {
              "name": "AccountName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Account name registered against the receiving BSB and account number.</p>",
              "example": "Acme Pty Ltd",
              "default": "Acme Pty Ltd",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "Bsb",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Required</strong>. BSB of the account the payment was credited to. Six digits, with or without the conventional hyphen after the third digit.</p>",
              "example": "802-985",
              "default": "802-985",
              "pattern": "^\\d{3}-?\\d{3}$"
            },
            {
              "name": "PayId",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned only when the payer addressed the payment to a PayID rather than to a BSB and account number. Holds the PayID value that was paid.</p>",
              "example": "payments@acme.com.au",
              "default": "payments@acme.com.au",
              "pattern": "^.{1,256}$"
            },
            {
              "name": "PayIdName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned alongside <code>PayId</code>. The registered display name that payers see when they address a payment to that PayID.</p>",
              "example": "ACME PAYMENTS",
              "default": "ACME PAYMENTS",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "RemitterName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Name of the remitting party as supplied by the payer's financial institution.</p>",
              "example": "J SMITH",
              "default": "J SMITH",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "SourceBsb",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. BSB of the payer's account, when the payer's institution discloses it.</p>",
              "example": "062-000",
              "default": "062-000",
              "pattern": "^\\d{3}-?\\d{3}$"
            },
            {
              "name": "SourceAccountNumber",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Payer's bank account number, when the payer's institution discloses it.</p>",
              "example": "12345678",
              "default": "12345678",
              "pattern": "^\\d{5,10}$"
            },
            {
              "name": "SourceAccountName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Populated for NPP transactions only, and holds the payer's bank account name. For Direct Entry transactions this field is not supplied — use <code>RemitterName</code> instead.</p>",
              "example": "JOHN A SMITH",
              "default": "JOHN A SMITH",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "PaymentDescription",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Free-text remittance description the payer attached to the payment.</p>",
              "example": "Invoice 10023",
              "default": "Invoice 10023",
              "pattern": "^.{0,280}$"
            },
            {
              "name": "EndToEndId",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Osko end-to-end identifier supplied by the payer and carried unchanged across the NPP. Echo it back on any related payment so the two legs can be matched.</p>",
              "example": "E2E-2026-0000123",
              "default": "E2E-2026-0000123",
              "pattern": "^[A-Za-z0-9\\/+?:().,'\\s-]{0,35}$"
            },
            {
              "name": "CreditorReferenceInformation",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Structured creditor reference supplied by the payer for reconciliation, carried end to end without alteration.</p>",
              "example": "RF18539007547034",
              "default": "RF18539007547034",
              "pattern": "^.{0,35}$"
            },
            {
              "name": "ReconciliationRuleReference",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned when the payment matched one of your active reconciliation rules. Holds the reference of the rule that matched. Absent when the payment was matched by account number alone.</p>",
              "example": "RULE-ACME-001",
              "default": "RULE-ACME-001",
              "pattern": "^.{1,64}$"
            },
            {
              "name": "CategoryPurposeCode",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. ISO 20022 category purpose code describing the nature of the payment, when the payer's institution supplies one.</p>",
              "example": "SALA",
              "default": "SALA",
              "pattern": "^[A-Z]{4}$"
            },
            {
              "name": "UltimateCreditorName",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Name of the ultimate beneficiary, where the payer nominated a party other than the account holder.</p>",
              "example": "Acme Holdings Pty Ltd",
              "default": "Acme Holdings Pty Ltd",
              "pattern": "^.{0,140}$"
            },
            {
              "name": "USINumber",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Unique Superannuation Identifier carried on superannuation contribution payments. Absent on all other payment types.</p>",
              "example": "12345678901SPN",
              "default": "12345678901SPN",
              "pattern": "^[A-Za-z0-9]{0,35}$"
            },
            {
              "name": "USICreditorScheme",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Optional</strong>. Scheme name that qualifies <code>USINumber</code> and identifies which superannuation identifier standard was used.</p>",
              "example": "USI",
              "default": "USI",
              "pattern": "^[A-Za-z0-9]{0,35}$"
            },
            {
              "name": "LedgerAccountNumber",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned when the funds were allocated to a Monoova ledger account. Holds the 16-digit ledger account number that was credited. Absent when no ledger allocation applies.</p>",
              "example": "4210000012345678",
              "default": "4210000012345678",
              "pattern": "^\\d{16}$"
            },
            {
              "name": "LedgerUniqueReference",
              "kind": "optional",
              "type": "string",
              "description": "<p><strong>Conditional</strong>. Returned alongside <code>LedgerAccountNumber</code>. Your own unique reference registered against that ledger account, used to tie the credit back to your customer record.</p>",
              "example": "ACME-LEDGER-0007",
              "default": "ACME-LEDGER-0007",
              "pattern": "^.{1,64}$"
            },
            {
              "name": "ReceiptNumber",
              "kind": "optional",
              "type": "integer<int32>",
              "nullable": true,
              "description": "<p><strong>Optional</strong>. Monoova receipt number raised for the credit. Null when no receipt was generated for the transaction. Pattern: <code>^\\d{1,10}$</code>.</p>",
              "example": 8842317,
              "default": 8842317,
              "format": "int32"
            },
            {
              "name": "RefundDetails",
              "kind": "optional",
              "type": "object",
              "description": "<p><strong>Conditional</strong>. Returned only when the received payment was subsequently refunded, in whole or in part. Absent for payments that were not refunded.</p>",
              "example": "",
              "schema": [
                {
                  "name": "InboundAmount",
                  "kind": "optional",
                  "type": "string",
                  "description": "<p><strong>Required</strong>. Amount originally received, in AUD to two decimal places, before any refund was applied.</p>",
                  "example": "150.00",
                  "default": "150.00",
                  "pattern": "^\\d{1,13}\\.\\d{2}$"
                },
                {
                  "name": "RefundAmount",
                  "kind": "optional",
                  "type": "string",
                  "description": "<p><strong>Required</strong>. Amount refunded to the payer, in AUD to two decimal places. Equal to <code>InboundAmount</code> on a full refund and lower on a partial refund.</p>",
                  "example": "150.00",
                  "default": "150.00",
                  "pattern": "^\\d{1,13}\\.\\d{2}$"
                },
                {
                  "name": "RefundId",
                  "kind": "optional",
                  "type": "string",
                  "description": "<p><strong>Required</strong>. Monoova identifier for the refund transaction. Quote it when raising a query about the refund.</p>",
                  "example": "991122334",
                  "default": "991122334",
                  "pattern": "^\\d{1,19}$"
                }
              ]
            }
          ],
          "modelRef": "#/components/schemas/WebhookNppReceivePaymentNotification",
          "isExpanded": true
        }
      ],
      "formDataParameters": [],
      "oAuthParameters": [],
      "cookieParameters": []
    },
    "responses": [
      {
        "statusCode": "200",
        "description": "<p><strong>Success.</strong> The notification passed validation and your endpoint has accepted responsibility for it. Return this as soon as the payload is persisted — do not wait for downstream processing. Monoova treats any 2xx as a successful delivery and will not retry.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"status\":\"Received\",\"webhookId\":1234567,\"receivedAt\":\"2026-09-10T14:32:12\"}",
            "description": "<p>Body your endpoint returns to acknowledge a notification. The body is optional — Monoova treats any 2xx status as a successful delivery — but returning it makes your acknowledgements easier to trace.</p>",
            "customType": "WebhookAcknowledgement",
            "schema": [
              {
                "name": "status",
                "kind": "optional",
                "type": "string<Received>",
                "description": "<p><strong>Required</strong>. Confirms the notification was accepted for processing. Return the literal value <code>Received</code>.</p>",
                "example": "Received",
                "default": "Received",
                "enum": [
                  "Received"
                ],
                "pattern": "^Received$"
              },
              {
                "name": "webhookId",
                "kind": "optional",
                "type": "integer<int64>",
                "description": "<p><strong>Optional</strong>. Echo of the <code>Webhookid</code> request header, so the acknowledgement can be matched to Monoova's delivery log. Pattern: <code>^\\d{1,19}$</code>.</p>",
                "example": 1234567,
                "default": 1234567,
                "format": "int64"
              },
              {
                "name": "receivedAt",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Optional</strong>. Date and time your endpoint accepted the notification, in ISO 8601 format.</p>",
                "example": "2026-09-10T14:32:12",
                "default": "2026-09-10T14:32:12",
                "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
              }
            ],
            "modelRef": "#/components/schemas/WebhookAcknowledgement",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "400",
        "description": "<p><strong>Bad Request.</strong> The notification could not be parsed, or a field failed your validation. Monoova will not retry a notification that is rejected with a 400, so return it only for a genuinely malformed payload — never for a transient fault on your side.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"status\":\"Rejected\",\"errorCode\":\"INVALID_PAYLOAD\",\"errorMessage\":\"Field 'Amount' is not a valid decimal value.\",\"webhookId\":1234567,\"receivedAt\":\"2026-09-10T14:32:12\"}",
            "description": "<p>Body your endpoint returns when a notification cannot be accepted. Returned with a 400, 401 or 500 status.</p>",
            "customType": "WebhookErrorResponse",
            "schema": [
              {
                "name": "status",
                "kind": "optional",
                "type": "string<Rejected | Unauthorised | Error>",
                "description": "<p><strong>Required</strong>. Processing outcome. Return <code>Rejected</code> with a 400, <code>Unauthorised</code> with a 401 and <code>Error</code> with a 500.</p>",
                "example": "Rejected",
                "default": "Rejected",
                "enum": [
                  "Rejected",
                  "Unauthorised",
                  "Error"
                ],
                "pattern": "^(Rejected|Unauthorised|Error)$"
              },
              {
                "name": "errorCode",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Machine-readable code identifying the failure, in upper snake case. Keep the value stable so Monoova support can group repeated failures.</p>",
                "example": "INVALID_PAYLOAD",
                "default": "INVALID_PAYLOAD",
                "pattern": "^[A-Z][A-Z0-9_]{2,49}$"
              },
              {
                "name": "errorMessage",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Human-readable explanation of the failure. Do not include payment data or credentials in this field.</p>",
                "example": "Field 'Amount' is not a valid decimal value.",
                "default": "Field 'Amount' is not a valid decimal value.",
                "pattern": "^.{1,500}$"
              },
              {
                "name": "webhookId",
                "kind": "optional",
                "type": "integer<int64>",
                "description": "<p><strong>Optional</strong>. Echo of the <code>Webhookid</code> request header, so the failure can be matched to Monoova's delivery log. Pattern: <code>^\\d{1,19}$</code>.</p>",
                "example": 1234567,
                "default": 1234567,
                "format": "int64"
              },
              {
                "name": "receivedAt",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Optional</strong>. Date and time your endpoint received the notification, in ISO 8601 format.</p>",
                "example": "2026-09-10T14:32:12",
                "default": "2026-09-10T14:32:12",
                "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
              }
            ],
            "modelRef": "#/components/schemas/WebhookErrorResponse",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "401",
        "description": "<p><strong>Unauthorised.</strong> The <code>Authorisation</code> header was missing or did not match the value registered on the subscription, or the <code>Verification-Signature</code> header failed SHA256 verification against the Monoova public key. Return this without processing the payload.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"status\":\"Unauthorised\",\"errorCode\":\"SIGNATURE_VERIFICATION_FAILED\",\"errorMessage\":\"Verification-Signature did not match the Monoova public key.\",\"webhookId\":1234567,\"receivedAt\":\"2026-09-10T14:32:12\"}",
            "description": "<p>Body your endpoint returns when a notification cannot be accepted. Returned with a 400, 401 or 500 status.</p>",
            "customType": "WebhookErrorResponse",
            "schema": [
              {
                "name": "status",
                "kind": "optional",
                "type": "string<Rejected | Unauthorised | Error>",
                "description": "<p><strong>Required</strong>. Processing outcome. Return <code>Rejected</code> with a 400, <code>Unauthorised</code> with a 401 and <code>Error</code> with a 500.</p>",
                "example": "Rejected",
                "default": "Rejected",
                "enum": [
                  "Rejected",
                  "Unauthorised",
                  "Error"
                ],
                "pattern": "^(Rejected|Unauthorised|Error)$"
              },
              {
                "name": "errorCode",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Machine-readable code identifying the failure, in upper snake case. Keep the value stable so Monoova support can group repeated failures.</p>",
                "example": "INVALID_PAYLOAD",
                "default": "INVALID_PAYLOAD",
                "pattern": "^[A-Z][A-Z0-9_]{2,49}$"
              },
              {
                "name": "errorMessage",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Human-readable explanation of the failure. Do not include payment data or credentials in this field.</p>",
                "example": "Field 'Amount' is not a valid decimal value.",
                "default": "Field 'Amount' is not a valid decimal value.",
                "pattern": "^.{1,500}$"
              },
              {
                "name": "webhookId",
                "kind": "optional",
                "type": "integer<int64>",
                "description": "<p><strong>Optional</strong>. Echo of the <code>Webhookid</code> request header, so the failure can be matched to Monoova's delivery log. Pattern: <code>^\\d{1,19}$</code>.</p>",
                "example": 1234567,
                "default": 1234567,
                "format": "int64"
              },
              {
                "name": "receivedAt",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Optional</strong>. Date and time your endpoint received the notification, in ISO 8601 format.</p>",
                "example": "2026-09-10T14:32:12",
                "default": "2026-09-10T14:32:12",
                "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
              }
            ],
            "modelRef": "#/components/schemas/WebhookErrorResponse",
            "isExpanded": true
          }
        ]
      },
      {
        "statusCode": "500",
        "description": "<p><strong>Internal Server Error.</strong> Your endpoint accepted the notification but could not process it because of a fault on your side. Monoova retries a notification that fails with a 5xx, so return this — rather than a 400 — whenever the failure is transient and a redelivery could succeed.</p>",
        "jsonExample": "",
        "isExpanded": true,
        "schema": [
          {
            "kind": "optional",
            "type": "object",
            "example": "{\"status\":\"Error\",\"errorCode\":\"DOWNSTREAM_UNAVAILABLE\",\"errorMessage\":\"Ledger service unavailable; retry delivery.\",\"webhookId\":1234567,\"receivedAt\":\"2026-09-10T14:32:12\"}",
            "description": "<p>Body your endpoint returns when a notification cannot be accepted. Returned with a 400, 401 or 500 status.</p>",
            "customType": "WebhookErrorResponse",
            "schema": [
              {
                "name": "status",
                "kind": "optional",
                "type": "string<Rejected | Unauthorised | Error>",
                "description": "<p><strong>Required</strong>. Processing outcome. Return <code>Rejected</code> with a 400, <code>Unauthorised</code> with a 401 and <code>Error</code> with a 500.</p>",
                "example": "Rejected",
                "default": "Rejected",
                "enum": [
                  "Rejected",
                  "Unauthorised",
                  "Error"
                ],
                "pattern": "^(Rejected|Unauthorised|Error)$"
              },
              {
                "name": "errorCode",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Machine-readable code identifying the failure, in upper snake case. Keep the value stable so Monoova support can group repeated failures.</p>",
                "example": "INVALID_PAYLOAD",
                "default": "INVALID_PAYLOAD",
                "pattern": "^[A-Z][A-Z0-9_]{2,49}$"
              },
              {
                "name": "errorMessage",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Required</strong>. Human-readable explanation of the failure. Do not include payment data or credentials in this field.</p>",
                "example": "Field 'Amount' is not a valid decimal value.",
                "default": "Field 'Amount' is not a valid decimal value.",
                "pattern": "^.{1,500}$"
              },
              {
                "name": "webhookId",
                "kind": "optional",
                "type": "integer<int64>",
                "description": "<p><strong>Optional</strong>. Echo of the <code>Webhookid</code> request header, so the failure can be matched to Monoova's delivery log. Pattern: <code>^\\d{1,19}$</code>.</p>",
                "example": 1234567,
                "default": 1234567,
                "format": "int64"
              },
              {
                "name": "receivedAt",
                "kind": "optional",
                "type": "string",
                "description": "<p><strong>Optional</strong>. Date and time your endpoint received the notification, in ISO 8601 format.</p>",
                "example": "2026-09-10T14:32:12",
                "default": "2026-09-10T14:32:12",
                "pattern": "^\\d{4}-\\d{2}-\\d{2}([T ]\\d{2}:\\d{2}:\\d{2}(\\.\\d{1,7})?)?$"
              }
            ],
            "modelRef": "#/components/schemas/WebhookErrorResponse",
            "isExpanded": true
          }
        ]
      }
    ],
    "hasXCodeSamples": false,
    "examples": {
      "languages": [
        {
          "id": "M_VY65sFiWwSr9-blsp1G",
          "language": "curl",
          "label": "cURL",
          "code": "curl --request POST \\\n     --url https://api.mpay.com.au/NPPRECEIVEPAYMENTEVENTWEBHOOK_TARGET_URL \\\n     --header 'accept: application/json' \\\n     --header 'content-type: application/json' \\\n     --header 'authorisation: ******' \\\n     --header 'verification-signature: e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=' \\\n     --header 'webhookid: 1234567' \\\n     --data-raw '{\n     \"TransactionId\": \"884231701\",\n     \"DateTime\": \"2026-09-10T14:32:11\",\n     \"Amount\": \"150.00\",\n     \"AccountNumber\": \"300000123\",\n     \"AccountName\": \"Acme Pty Ltd\",\n     \"Bsb\": \"802-985\",\n     \"PayId\": \"payments@acme.com.au\",\n     \"PayIdName\": \"ACME PAYMENTS\",\n     \"RemitterName\": \"J SMITH\",\n     \"SourceBsb\": \"062-000\",\n     \"SourceAccountNumber\": \"12345678\",\n     \"SourceAccountName\": \"JOHN A SMITH\",\n     \"PaymentDescription\": \"Invoice 10023\",\n     \"EndToEndId\": \"E2E-2026-0000123\",\n     \"CreditorReferenceInformation\": \"RF18539007547034\",\n     \"ReconciliationRuleReference\": \"RULE-ACME-001\",\n     \"CategoryPurposeCode\": \"SALA\",\n     \"UltimateCreditorName\": \"Acme Holdings Pty Ltd\",\n     \"USINumber\": \"12345678901SPN\",\n     \"USICreditorScheme\": \"USI\",\n     \"LedgerAccountNumber\": \"4210000012345678\",\n     \"LedgerUniqueReference\": \"ACME-LEDGER-0007\",\n     \"ReceiptNumber\": 8842317,\n     \"RefundDetails\": {\n     \"InboundAmount\": \"150.00\",\n     \"RefundAmount\": \"150.00\",\n     \"RefundId\": \"991122334\"\n     }\n     }'"
        },
        {
          "id": "q9twnjd7sKlmZFSkD3bQ8",
          "language": "javascript",
          "label": "javascript",
          "code": "var myHeaders = new Headers();\nmyHeaders.append(\"accept\", \"application/json\");\nmyHeaders.append(\"content-type\", \"application/json\");\nmyHeaders.append(\"authorisation\", \"******\");\nmyHeaders.append(\"verification-signature\", \"e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=\");\nmyHeaders.append(\"webhookid\", \"1234567\");\n\nvar raw = JSON.stringify({\n   \"TransactionId\": \"884231701\",\n   \"DateTime\": \"2026-09-10T14:32:11\",\n   \"Amount\": \"150.00\",\n   \"AccountNumber\": \"300000123\",\n   \"AccountName\": \"Acme Pty Ltd\",\n   \"Bsb\": \"802-985\",\n   \"PayId\": \"payments@acme.com.au\",\n   \"PayIdName\": \"ACME PAYMENTS\",\n   \"RemitterName\": \"J SMITH\",\n   \"SourceBsb\": \"062-000\",\n   \"SourceAccountNumber\": \"12345678\",\n   \"SourceAccountName\": \"JOHN A SMITH\",\n   \"PaymentDescription\": \"Invoice 10023\",\n   \"EndToEndId\": \"E2E-2026-0000123\",\n   \"CreditorReferenceInformation\": \"RF18539007547034\",\n   \"ReconciliationRuleReference\": \"RULE-ACME-001\",\n   \"CategoryPurposeCode\": \"SALA\",\n   \"UltimateCreditorName\": \"Acme Holdings Pty Ltd\",\n   \"USINumber\": \"12345678901SPN\",\n   \"USICreditorScheme\": \"USI\",\n   \"LedgerAccountNumber\": \"4210000012345678\",\n   \"LedgerUniqueReference\": \"ACME-LEDGER-0007\",\n   \"ReceiptNumber\": 8842317,\n   \"RefundDetails\": {\n      \"InboundAmount\": \"150.00\",\n      \"RefundAmount\": \"150.00\",\n      \"RefundId\": \"991122334\"\n   }\n});\n\nvar requestOptions = {\n   method: 'POST',\n   headers: myHeaders,\n   body: raw,\n   redirect: 'follow'\n};\n\nfetch(\"https://api.mpay.com.au/NPPRECEIVEPAYMENTEVENTWEBHOOK_TARGET_URL\", requestOptions)\n   .then(response => response.text())\n   .then(result => console.log(result))\n   .catch(error => console.log('error', error));"
        },
        {
          "id": "-FwL390x7tUHbevukEQla",
          "language": "ruby",
          "label": "Ruby",
          "code": "require \"uri\"\nrequire \"json\"\nrequire \"net/http\"\n\nurl = URI(\"https://api.mpay.com.au/NPPRECEIVEPAYMENTEVENTWEBHOOK_TARGET_URL\")\n\nhttps = Net::HTTP.new(url.host, url.port)\nhttps.use_ssl = true\n\nrequest = Net::HTTP::Post.new(url)\nrequest[\"accept\"] = \"application/json\"\nrequest[\"content-type\"] = \"application/json\"\nrequest[\"authorisation\"] = \"******\"\nrequest[\"verification-signature\"] = \"e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=\"\nrequest[\"webhookid\"] = \"1234567\"\nrequest.body = JSON.dump({\n   \"TransactionId\": \"884231701\",\n   \"DateTime\": \"2026-09-10T14:32:11\",\n   \"Amount\": \"150.00\",\n   \"AccountNumber\": \"300000123\",\n   \"AccountName\": \"Acme Pty Ltd\",\n   \"Bsb\": \"802-985\",\n   \"PayId\": \"payments@acme.com.au\",\n   \"PayIdName\": \"ACME PAYMENTS\",\n   \"RemitterName\": \"J SMITH\",\n   \"SourceBsb\": \"062-000\",\n   \"SourceAccountNumber\": \"12345678\",\n   \"SourceAccountName\": \"JOHN A SMITH\",\n   \"PaymentDescription\": \"Invoice 10023\",\n   \"EndToEndId\": \"E2E-2026-0000123\",\n   \"CreditorReferenceInformation\": \"RF18539007547034\",\n   \"ReconciliationRuleReference\": \"RULE-ACME-001\",\n   \"CategoryPurposeCode\": \"SALA\",\n   \"UltimateCreditorName\": \"Acme Holdings Pty Ltd\",\n   \"USINumber\": \"12345678901SPN\",\n   \"USICreditorScheme\": \"USI\",\n   \"LedgerAccountNumber\": \"4210000012345678\",\n   \"LedgerUniqueReference\": \"ACME-LEDGER-0007\",\n   \"ReceiptNumber\": 8842317,\n   \"RefundDetails\": {\n      \"InboundAmount\": \"150.00\",\n      \"RefundAmount\": \"150.00\",\n      \"RefundId\": \"991122334\"\n   }\n})\n\nresponse = https.request(request)\nputs response.read_body\n"
        },
        {
          "id": "Avk0LcZjG4kN-h3ykG6Iv",
          "language": "python",
          "label": "Python",
          "code": "import requests\nimport json\n\nurl = \"https://api.mpay.com.au/NPPRECEIVEPAYMENTEVENTWEBHOOK_TARGET_URL\"\n\npayload = json.dumps({\n   \"TransactionId\": \"884231701\",\n   \"DateTime\": \"2026-09-10T14:32:11\",\n   \"Amount\": \"150.00\",\n   \"AccountNumber\": \"300000123\",\n   \"AccountName\": \"Acme Pty Ltd\",\n   \"Bsb\": \"802-985\",\n   \"PayId\": \"payments@acme.com.au\",\n   \"PayIdName\": \"ACME PAYMENTS\",\n   \"RemitterName\": \"J SMITH\",\n   \"SourceBsb\": \"062-000\",\n   \"SourceAccountNumber\": \"12345678\",\n   \"SourceAccountName\": \"JOHN A SMITH\",\n   \"PaymentDescription\": \"Invoice 10023\",\n   \"EndToEndId\": \"E2E-2026-0000123\",\n   \"CreditorReferenceInformation\": \"RF18539007547034\",\n   \"ReconciliationRuleReference\": \"RULE-ACME-001\",\n   \"CategoryPurposeCode\": \"SALA\",\n   \"UltimateCreditorName\": \"Acme Holdings Pty Ltd\",\n   \"USINumber\": \"12345678901SPN\",\n   \"USICreditorScheme\": \"USI\",\n   \"LedgerAccountNumber\": \"4210000012345678\",\n   \"LedgerUniqueReference\": \"ACME-LEDGER-0007\",\n   \"ReceiptNumber\": 8842317,\n   \"RefundDetails\": {\n      \"InboundAmount\": \"150.00\",\n      \"RefundAmount\": \"150.00\",\n      \"RefundId\": \"991122334\"\n   }\n})\nheaders = {\n   'accept': 'application/json',\n   'content-type': 'application/json',\n   'authorisation': '******',\n   'verification-signature': 'e+AFAj2W69rAwbsGn+rSSnFm2ISEblo0MXnx9Qtoh2k5mst1cEEpcrVSzGLjzOPlEL2Ea/iYLbFGzDdxVRTcNLINOhsXM/smimNjBt8sq30FbvSNMjlfDnrZ6FOIkl3E3cu9B+M4OVL8HafPohb67IRNDNyCnCvBM10qHrioiak=',\n   'webhookid': '1234567'\n}\n\nresponse = requests.request(\"POST\", url, headers=headers, data=payload)\n\nprint(response.text)\n"
        }
      ],
      "selectedLanguageId": "M_VY65sFiWwSr9-blsp1G"
    },
    "results": {
      "languages": [
        {
          "id": "kfJawLarxx4JnY23Ip6WQ",
          "language": "200",
          "code": "// Success. The notification passed validation and your endpoint has accepted responsibility for it. Return this as soon as the payload is persisted — do not wait for downstream processing. Monoova treats any 2xx as a successful delivery and will not retry.\n{\n  \"status\": \"Received\",\n  \"webhookId\": 1234567,\n  \"receivedAt\": \"2026-09-10T14:32:12\"\n}"
        },
        {
          "id": "IUkSw29cIaEi4E5vX4ixs",
          "language": "400",
          "code": "// Bad Request. The notification could not be parsed, or a field failed your validation. Monoova will not retry a notification that is rejected with a 400, so return it only for a genuinely malformed payload — never for a transient fault on your side.\n{\n  \"status\": \"Rejected\",\n  \"errorCode\": \"INVALID_PAYLOAD\",\n  \"errorMessage\": \"Field 'Amount' is not a valid decimal value.\",\n  \"webhookId\": 1234567,\n  \"receivedAt\": \"2026-09-10T14:32:12\"\n}"
        },
        {
          "id": "OhfhoPZt0NB1CtpGSOXF9",
          "language": "401",
          "code": "// Unauthorised. The Authorisation header was missing or did not match the value registered on the subscription, or the Verification-Signature header failed SHA256 verification against the Monoova public key. Return this without processing the payload.\n{\n  \"status\": \"Rejected\",\n  \"errorCode\": \"INVALID_PAYLOAD\",\n  \"errorMessage\": \"Field 'Amount' is not a valid decimal value.\",\n  \"webhookId\": 1234567,\n  \"receivedAt\": \"2026-09-10T14:32:12\"\n}"
        },
        {
          "id": "2_a-SnKIQCLpRIiC8rWLD",
          "language": "500",
          "code": "// Internal Server Error. Your endpoint accepted the notification but could not process it because of a fault on your side. Monoova retries a notification that fails with a 5xx, so return this — rather than a 400 — whenever the failure is transient and a redelivery could succeed.\n{\n  \"status\": \"Rejected\",\n  \"errorCode\": \"INVALID_PAYLOAD\",\n  \"errorMessage\": \"Field 'Amount' is not a valid decimal value.\",\n  \"webhookId\": 1234567,\n  \"receivedAt\": \"2026-09-10T14:32:12\"\n}"
        }
      ],
      "selectedLanguageId": "kfJawLarxx4JnY23Ip6WQ"
    }
  },
  "children": [
    {
      "text": ""
    }
  ]
}