Configure test_webhook_url and live_webhook_url in the reseller dashboard. Each environment
only receives events from matching API keys.Delivery#
Webhooks are sent as POST requests with Content-Type: application/json.Important: Return any 2xx status promptly. Failed deliveries may be retried — the same event may arrive more than once. Handle events idempotently.
Verify signatures#
Important: Always verify x-ciao-signature before processing a webhook. Reject requests with invalid signatures.
Compute the expected value as:HMAC-SHA256(json_encode(payload), your_api_token)
Where payload is the decoded JSON body and your_api_token is your API secret for the matching
environment.Envelope#
{
"event": "subscription.cancel_requested",
"data": { },
"created_at": "2026-07-10T14:00:01.000000Z"
}
subscription.cancel_requested#
Important: Stop billing immediately, then call Confirm cancellation. The partner is not canceled until you confirm.
Sent when a partner cancels a live subscription that is billed through your reseller account.{
"event": "subscription.cancel_requested",
"data": {
"access_code": "AbC123XyZ456789",
"reseller_subscription_reference": "sub-order-4421"
},
"created_at": "2026-07-10T14:00:01.000000Z"
}
| Field | Description |
|---|
access_code | Pass to Confirm cancellation |
reseller_subscription_reference | Your recurring-order ID, if stored on first cycle; omitted if never set |
What to do#
1.
Stop scheduling future billing cycles for this subscription.
3.
The partner receives subscription.cancelled after you confirm.
Duplicate webhooks are not sent while a cancel request is already pending for the same
subscription. Modified at 2026-07-21 13:41:45