Verify every request
Read the raw body before parsing JSON and calculate:X-CopBy-Signature using a constant-time comparison. Also read:
Reject an invalid signature before processing the payload.
Return quickly
Persist the event ID, enqueue your work, and return2xx. Duplicate event IDs must return success
without applying the event twice.
COP By retries failed deliveries after approximately 1 minute, 5 minutes, 30 minutes, 2 hours, and
12 hours.
Reconcile
Webhooks can arrive late or more than once. PollGET /api/integrations/breb/payouts/{payoutId} as a
fallback and use the current payout resource to resolve discrepancies.
/api/breb/webhook is the inbound Bridge-to-COP-By endpoint. Partners should not call it. Your
integration receives the outbound partnerPayoutStatus webhook documented in API Reference.BRE-B payouts
Review the payout flow that produces these events.
Errors and lifecycle
Handle terminal, recoverable, and idempotent outcomes.