1. Card Present Billpocket
  • API Docs Mexico 🇲🇽
  • Online Payments
    • Release Notes
    • Card Payments
      • Request a card token
      • Make a charge or deferred charge
      • Create payment (tokenless)
      • Request deferred options
      • Refund a transaction
      • Authorize payments
      • Preauthorization (tokenless)
      • Void a transaction
      • Reauthorize payments
      • Capture an authorized payment
      • Bin Info V2
      • Bin Info
      • Validate OTP
      • Verify Account
    • One-Click and Scheduled Payments
      • Request a recurring charge token
      • Create a recurring charge
      • Make an One-click payment
      • Update recurring charge card data
      • Cancel a recurring charge
      • Update a recurring charge
      • Add a temporary charge or discount
      • Authorize payments
      • Capture an authorized payment
      • Get recurring charge Info
    • Transfer in
      • Get Bank List
      • Request a Transfer In token
      • Init Transaction
      • Get Status
    • Transfer Out
      • Get Bank List
      • Get Bank List V2
      • Request a Transfer Out token
      • Init Transaction
      • Get Status
      • Balance for Payouts
    • Smartlinks
      • Create a Smartlink
      • Get a Smartlink
      • Delete a smartlink
      • Update a Smartlink
    • Payment Button
      • Create a payment button
    • Analytics
      • Get transactions list v1
      • Get transactions list v2
    • Chargebacks
      • Query chargebacks
      • Request chargeback export
    • Commissions
      • Get Commission Configuration
    • Payment Credentials
      • Create a credential
      • Activate or deactivate
      • Delete credential
      • Regenerate a credential
      • Update credential
      • Advanced search
      • Search credentials
    • Platform Status
      • Get platform status
      • Get gateway status
    • Settlement
      • Query settlement
    • Subscription Transactions
      • Get subscription transactions
  • Card Present Billpocket
    • Get Started
      • Create Account
      • User Token
      • API Keys
    • Webhooks
      • Webhooks — Transfer Funds (v1)
      • Webhooks — Transfer Funds to Your Bank Account
      • Transfer Funds Errors
    • Terminals
      • App Review
      • Splash Screen
    • Card Present Payment Services
      • Cloud Terminal API
        • Collect card payments
        • Print Ticket
        • Cancel Push Notification
        • Get transaction status
        • Collect card payments v2
      • App-to-App
        • Android intents
        • App to App — iOS
        • App to App — Mobile Web
      • Terminal SDK
        • Terminal SDK
        • Android SDK errors
    • Card not Present Billpocket Services
      • 3DS Checkout
        • Create checkout
        • Get checkout details
      • E-commerce Flex
        • Get token
        • Validate token
        • Collect payments
        • Refund
        • Capture an authorized payment
        • Get status
    • Catalogs
      • States
      • Municipalities
      • Tax companies
      • Commercial activities
    • User Settings
      • Create user
    • Accounts
      • Clabe Account Setup
        • Add CLABE account
      • Deposit Accounts
        • Add or update CLABE account
    • Transactions
      • Transaction List
        • Get token
        • Get transaction list
        • Get transaction list v2
        • Get transaction list v3
        • Get transaction list v4
      • Cancel Payments
        • Cancel payments Error Codes
        • Cancel payments
  • API Raw Card Present
    • The Amount Object
    • Error Catalog
    • Key Exchange Process
    • Release Notes
    • Test Data
    • One-time payments
      • Single payment
    • Two-step-payments
      • Authorization and capture
    • Voids & Refunds
      • Refund a transaction
    • Card information
      • Get BIN Info
      • Balance inquiries
      • Bin Info V2
      • Request deferred options
    • Query Transactions
      • Transaction Search
    • Webhooks
      • Webhooks — Introduction
      • Good Practices
      • Webhooks — Card Payments
      • Webhooks — Refunds
      • Check Your Webhooks
  • Kushki One
    • Cloud Services
      • Payment
        • Charge
        • Authorization (Pre-auth)
        • Capture
        • Re-authorization
        • Post-tip
        • Void
        • Refund
        • Abort
      • Search
        • Transaction Search
      • Print
        • Create Print Job
        • Get Print Job Status
    • Local Services
      • Print
        • Create Print Job
        • Get Print Job Status
        • Print Job Webhook (inbound — implemented by your POS)
      • Payment
        • Charge
        • Authorization (Pre-auth)
        • Capture
        • Re-authorization
        • Post-tip
        • Void
        • Refund
        • Abort
      • Search
        • Transaction Search — Online
        • Transaction Search — Local
  • Appian - Submerchant Register
    • Submerchant Validation in Batch
    • Query submerchant status by requestId/submerchantId
    • Submerchant Document Upload
    • Get submerchantIds
    • Get credentials for submerchants
  • Schemas
    • RequestBodies
      • one-and-two-step-payment
    • Card
    • Channel
    • Amount-cash-in
    • ChargebackListResponse
    • StatusComponent
    • SettlementDateRangeRequest
    • SubscriptionTransactionsResponse
    • amount
    • AmountWithTaxes
    • PrintJobRequest
    • networkToken
    • ChargebackItem
    • SettlementTicketRequest
    • SubscriptionTransaction
    • extra_taxes
    • AmountCore
    • CommandText
    • currency
    • ErrorResponse400
    • ErrorResponse
    • SettlementResponse
    • webhooksItem
    • card
    • ExtraTaxes
    • CommandColumns
    • Amount
    • Country
    • ErrorResponse401
    • SettlementRecord
    • card_details
    • ColumnItem
    • extraTaxes
    • ErrorResponse403
    • enc_tlv
    • TransactionResponse
    • CommandDivider
    • Deferred
    • payment_method
    • ErrorResponse500
    • deferred
    • RawResponse
    • CommandFeed
    • Metadata
    • pos_details
    • CardData
    • CommandSpace
    • ContactDetails
    • contact_details
    • sub_merchant
    • AmountWithTip
    • CommandCut
    • documentType
    • Subscription
    • metadata
    • LinkFailure
    • CommandImage
    • orderDetails
    • Language
    • TransactionSearchRequest
    • CommandQR
    • Shipping Address
    • payment_submethod
    • CommandBarcode
    • Billing-Address
    • SubscriptionUpdate
    • PrinterError
    • product
    • SubscriptionAdjustmentRequest
    • PrintJobStatus
    • threeDomainSecure
    • PrintWebhookPayload
    • webhooks
    • headers
    • webhooksChargeback
    • citMit
    • network
    • binInfo
    • messageFields
    • UnexpectedErrorResponse
    • transactionType
    • ExternalReferenceId
    • ExternalSubscriptionId
BienvenidaPerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
BienvenidaPerú 🇵🇪México 🇲🇽
Ecuador 🇪🇨Colombia 🇨🇴Chile 🇨🇱
  1. Card Present Billpocket

Webhooks

Webhooks notify your application when events occur — a transaction is approved or declined, a refund is processed, or a SPEI fund transfer completes. Billpocket sends a POST request to your configured endpoint with a JSON payload containing the full event details.
INFO
Webhooks are asynchronous. Notifications are usually sent immediately, but occasional delays can occur. Design your integration to handle delayed or out-of-order delivery.

Endpoint requirements#

Your webhook endpoint must:
Accept HTTP POST requests
Have a valid SSL certificate (HTTPS)
Respond with HTTP 200 within 2 seconds
Accept JSON payloads
Have a URL no longer than 300 characters

Event types#

EventDescription
Approved transactionsFired when a card payment is approved
Rejected transactionsFired when a card payment is declined
RefundsFired when a refund is approved or rejected
Transfer funds to your bank accountDaily SPEI settlement notification sent at 01:00 AM CDMX (UTC-6)

Register your endpoint#

1.
Log in to your dashboard with the correct environment credentials.
2.
Navigate to Configuración > Integraciones.
3.
Enter your endpoint URL in the Webhook General section.
4.
Select the event types you want to subscribe to.
5.
Click Guardar.
INFO
The endpoint must respond with HTTP 200 on registration to be saved successfully. Changes may take a few minutes to take effect.

Security — signature verification#

Every webhook POST includes two headers to verify the request origin:
HeaderDescription
X-BP-SignatureBase64-encoded RSA signature of the payload
X-BP-SignatureKeyKey index of the private key used to sign the message
Retrieve the matching public key by appending the key index to:
https://keys.billpocket.com/webhook/
Example — for key index k1:
PEM: https://keys.billpocket.com/webhook/k1.pem
DER: https://keys.billpocket.com/webhook/k1.der
INFO
Cache the public key on your side to speed up verification. Keys don't change over time, but the key index may be updated to use a new pair.

Verification examples#

Java
PHP
Node.js

Approved transactions#

Configure#

In the dashboard: Configuración > Integraciones → set your webhook URL in Webhook General and enable Transacciones Aprobadas.

Payload fields#

FieldTypeDescription
resultstring"aprobada"
amountstringTransaction amount
tipstringTip amount (if applicable)
paymentsintegerNumber of MSI installments (0 = one-time)
authorizationTimestringAuthorization timestamp (RFC 3339)
referencestringTransaction description
transactionidstringKushki-generated transaction ID
authorizationstringAuthorization string
creditcardstringLast 4 digits of the PAN
cardtypestringVISA, MASTERCARD, CARNET, AMERICAN EXPRESS
arqcstringEMV Authorization Request Cryptogram
userIDintegerID of the user who made the transaction
aidstringEMV Chip Application ID
applabelstringEMV Chip Application Label
urlstringUnique identifier to access the transaction ticket
emailstringEmail the ticket was sent to
phonestringPhone the ticket was sent to
cardBrandstringCard network
cardIssuerstringIssuing bank
cardCountrystringCard country code (ISO 3166-1 alpha-2)
cardClassstringDEBIT or CREDIT
launchTimestringTimestamp the transaction was sent
maskedPANstringMasked card number
uniqueReferencestringClient-generated unique identifier (UUID)

Example#

{
  "cardBrand": "MASTERCARD",
  "cardIssuer": "SANTANDER",
  "cardCountry": "MX",
  "cardClass": "CREDIT",
  "launchTime": "2024-05-29T11:01:27.360-0600",
  "userID": 61000,
  "authorizationTime": "2024-05-29T11:01:27.360-0600",
  "result": "aprobada",
  "amount": "100.00",
  "payments": 0,
  "transactionid": "128010",
  "authorization": "BP3500",
  "creditcard": "0009",
  "cardtype": "MASTERCARD",
  "arqc": "A38051D19B2548E3",
  "aid": "A0000000041010",
  "applabel": "Mastercard",
  "url": "face3142cb4d32a545f42d278b8cf4ce5ea3d0b1",
  "maskedPAN": "500000******0009",
  "uniqueReference": "d6732f94-6cf2-4dfb-aed7-11b64b739407"
}

Rejected transactions#

Configure#

In the dashboard: Configuración > Integraciones → enable Transacciones Rechazadas in the Webhook General section.

Payload fields#

Same fields as approved transactions, with result: "rechazadaProsa". Fields authorization, url, email, and phone are not returned on rejections.

Example#

{
  "cardBrand": "MASTERCARD",
  "cardIssuer": "SANTANDER",
  "cardCountry": "MX",
  "cardClass": "CREDIT",
  "launchTime": "2024-05-29T10:46:52.221-0600",
  "userID": 61000,
  "authorizationTime": "2024-05-29T10:46:52.221-0600",
  "result": "rechazadaProsa",
  "amount": "99.00",
  "payments": 0,
  "transactionid": "128011",
  "creditcard": "0009",
  "cardtype": "MASTERCARD",
  "arqc": "6FEC34124C9AAEEB",
  "aid": "A0000000041010",
  "applabel": "Mastercard",
  "maskedPAN": "500000******0009",
  "uniqueReference": "d6732f94-6cf2-4dfb-aed7-11b64b739407"
}

Refunds#

Configure#

In the dashboard: Configuración > Integraciones → enable Transacciones Aprobadas and/or Transacciones Rechazadas under the Devoluciones tab.

Payload fields#

FieldTypeDescription
resultstring"aprobada", "rechazadaRiesgo", "rechazadaProsa", "rechazada", or "pendiente"
transactionTypestring"devolución"
transactionRefundedIdstringOriginal transaction ID that was refunded
amountstringRefund amount
transactionidstringRefund transaction ID
authorizationstringAuthorization string (approved only)
creditcardstringLast 4 digits of the PAN
cardtypestringCard network
cardBrandstringCard Issuer Network
cardCountrystringCard country code (ISO 3166-1 alpha-2)
cardClassstringDEBIT or CREDIT
userIDintegerUser ID
urlstringTransaction ticket identifier (approved only)
maskedPANstringMasked card number
uniqueReferencestringClient-generated unique identifier

Examples#

Approved refund:
{
  "cardBrand": "VISA",
  "cardCountry": "US",
  "cardClass": "CREDIT",
  "uniqueReference": "d6732f94-6cf2-4dfb-aed7-11b64b739407",
  "launchTime": "2024-08-16T10:02:37.965-0600",
  "userID": 61000,
  "authorizationTime": "2024-08-16T10:02:37.965-0600",
  "result": "aprobada",
  "amount": "1018.0",
  "payments": 0,
  "transactionid": "128013",
  "authorization": "BP4160",
  "creditcard": "0002",
  "cardtype": "VISA",
  "url": "19c6f19bc1a7a00a1d76021aa5eaef2627aba950",
  "maskedPAN": "400000******0002",
  "transactionType": "devolucion",
  "transactionRefundedId": "128012"
}

Got a suggestion on this documentation? Contact us.
Modified at 2026-07-09 22:28:09
Previous
API Keys
Next
Webhooks — Transfer Funds (v1)
Built with