# Webhooks

A webhook is a subscription that tells Ripple Collections to notify your system when something happens, instead of you polling to find out.

You register a callback URL against an event type. When an event of that type occurs, we send an HTTP request to your URL carrying the event payload. This is how you track collections, settlements, and account activity in real time — a payer completing a payment, a settlement failing, an account balance changing.

Webhooks are created one per event type. Subscribing to several event types creates several webhook records, each independently retrievable and updatable.

## Event types

Events are grouped by the resource they concern.

| Resource | Event types |
|  --- | --- |
| [Accounts](/pt-br/products/collections/concepts/accounts) | `ACCOUNT_CREATED`, `ACCOUNT_STATUS_CHANGED`, `ACCOUNT_BALANCE_UPDATED` |
| [Channels](/pt-br/products/collections/concepts/channels) | `CHANNEL_CREATED`, `CHANNEL_ARCHIVED` |
| [Partners](/pt-br/products/collections/concepts/partners) | `PARTNER_STATUS_CHANGED` |
| [Transactions](/pt-br/products/collections/concepts/transactions) | `TRANSACTION_STATUS_CHANGED` |
| [Settlements](/pt-br/products/collections/concepts/settlements) | `SETTLEMENT_INITIATED`, `SETTLEMENT_COMPLETED`, `SETTLEMENT_FAILED` |
| Wallet addresses | `WALLET_ADDRESS_CREATED`, `WALLET_ADDRESS_ROTATED` |
| Webhooks | `WEBHOOK_CREATED`, `WEBHOOK_UPDATED`, `WEBHOOK_DELETED` |


## Verifying that a webhook came from us

Anyone can send an HTTP request to your callback URL. Signature verification is how you establish that a given request actually originated from Ripple Collections and was not tampered with in transit.

When you create a webhook, the response includes a `signature_verification_key`. This is a base64-encoded symmetric secret, and it is returned at creation time — persist it securely then, because it is what you use to validate every subsequent payload.

Each delivered webhook carries a timestamp header and an HMAC-SHA256 signature computed over the payload. Your handler recomputes the signature using your stored key and compares.

Treat this as required rather than optional. An unverified webhook endpoint will act on anything sent to it.

For the verification procedure and code samples, see [Verify webhook signatures](/pt-br/products/collections/guides/verifying-webhooks).

## API operations

- [Create webhooks](/products/collections/api/collections/webhooks/createwebhooks): Create one webhook per event type supplied.
- [List webhooks](/products/collections/api/collections/webhooks/listwebhooks): Retrieve your existing webhook subscriptions.
- [Get a webhook](/products/collections/api/collections/webhooks/getwebhook): View the details of a single webhook subscription.
- [Update a webhook](/products/collections/api/collections/webhooks/updatewebhook): Change an existing subscription, for example to move it to a new callback URL.
- [Delete a webhook](/products/collections/api/collections/webhooks/deletewebhook): Remove a webhook subscription you no longer need.