Log in
Use Portal login to exchange your provisioned username and password for anaccess_token.
Send the returned token with Authorization: Bearer <access_token> for every
endpoint on this page.
Register an endpoint
Call Create webhook with your callbackurl. The reference contains the request and response example.
Store signing_secret before responding to the user. It is returned only
by this create response and cannot be read, changed, or recovered later. If it
is lost, register a new endpoint and update your receiver to use the new
secret.
There is no callback URL in end-user KYC or payment requests. Every active
registered endpoint receives a durable delivery for each new merchant event.
New endpoints do not receive a replay of older events.
Manage endpoints
An endpoint cannot be reactivated or edited after deletion. Register a new one
instead. Deleting it does not change its signing secret; it simply stops future
delivery to that endpoint.
Verify deliveries
AgentBank posts JSON to your endpoint with these headers:
Read the exact raw UTF-8 body before parsing JSON. The HMAC input is:
signing_secret. Compare the
v1=<hex> value in constant time. Also enforce a reasonable timestamp window
in your receiver, persist the delivery ID before processing, and return 2xx
only after durable acceptance.
Delivery model
The payload has this envelope:end_user.kyc.acceptedandend_user.rail_readiness.updatedpayment.created,payment.funding_required,payment.completed,payment.failed,payment.cancelled, andpayment.updatedpayment.timeline_step.recorded, whosedata.timeline_stepis a newly observed timeline entry and whose data includes a fresh payment snapshot
429, and 5xx
responses are retried with backoff. Use x-agentbank-delivery-id to
deduplicate; do not assume ordering across endpoints or use a duplicate as a
second payment instruction.

