Webhooks
Advance and payment events occur after your request returns. Subscribe to receive them instead of polling.
Subscribing
Code
Omit eventTypes to receive all events, including future ones.
Store the signing secret immediately
The signing secret is returned only in this response. If the response is lost, see Idempotent Requests before retrying.
Technical Details
| Requirement | Detail |
|---|---|
| Endpoint | Public https URL. |
| Refused addresses | Private, loopback and link-local. |
| Redirects | Not followed. |
| Success | Any 2xx response. |
| Retries | Other responses are retried for about 28 hours. |
| Retired endpoints | Return 410 to stop deliveries and revoke the subscription. |
Authentication
Each delivery includes Lunch-Signature: t=<unix seconds>,v1=<hex>: an HMAC-SHA256 of
"<timestamp>.<raw body>", keyed with your signing secret.
Code
Check the timestamp
Reject deliveries older than five minutes. A valid signature does not prove a delivery is recent.
Webhook Idempotency
Delivery is at-least-once. Deduplicate on Lunch-Delivery, which is constant across retries.
Ordering
Delivery order is not guaranteed, and out-of-order deliveries are not corrected. A retried delivery can arrive after a later one.
partner.invoice.factoredUpdatedincludes asequence. Ignore events whosesequenceis not greater than the last one processed for that invoice.- Do not order by
occurredAt. It is the transaction start time. Use it for logging.
Events
Event names use loan for advances.
| Event | Description |
|---|---|
partner.organization.added | An organization you synced exists at Lunch. |
partner.organization.optedIn | The organization has completed onboarding. |
partner.organization.remittanceUpdated | The destination for the organization's funds has changed. |
partner.invoice.created | An invoice you synced exists at Lunch. |
partner.invoice.paid | The payor has paid the invoice. |
partner.invoice.factoredUpdated | The advance's financing state has changed: REQUESTED, FUNDING, FUNDED or REPAID. |
partner.loan.created | An advance has been created. |
partner.loan.issued | The vendor has been paid the advance. |
partner.loan.paid | The advance has settled. |
Managing Subscriptions
| Action | Call |
|---|---|
| List active subscriptions (secrets excluded) | GET /v1/webhooks |
| Delete a subscription | DELETE /v1/webhooks/{reference} |

