Webhooks

Studio profile

Configuration

Where refund.requested / refund.approved / refund.denied events are delivered. You also get an email for every request awaiting review either way.
Every sale (or giveaway claim) sends a signed purchase event here so your redemption backend learns which token belongs to which listing — without it, buyers hit "Token not registered" when they redeem. Running the FlipKey.gg starter kit? The path is /api/mirror/token-mint. Leave blank to receive purchase events at the main Webhook URL instead.

Credentials

Your webhook secret signs every payload we send you and powers the listing link test — copy it into your backend as FLIPKEY_WEBHOOK_SECRET. Your API key authenticates server-to-server calls (X-API-Key header). Owner access only; every reveal and rotation is audit-logged.

••••••••••••••••
••••••••••••••••

What we send

FlipKey.gg POSTs JSON to your Webhook URL, signed with an X-FlipKey-Signature header — an HMAC-SHA256 of the raw request body using your webhook secret. Verify it before trusting the request. Events:

  • purchase — a license was sold and minted: { event, orderRef, tokenId, walletAddress, playerAddress, dropId, priceUsd, txHash, timestamp }
  • activation — a license was redeemed: { event, tokenId, playerAddress, txHash, contractAddress, timestamp }
  • refund.requested / refund.executed / refund.denied — delivered to your refund webhook endpoint. A hosted or one-command key station is wired here automatically (https://<station>/api/refund-webhook); on refund.executed the station marks the delivered key revoked. Revoking it on the platform (Steamworks → CD keys) is your step — Steam is never told about a refund by anyone else. { event, order_ref, drop_id, token_id, contract_address, platform, buyer_wallet, price_usd, kind, purchase_status, burn_tx_hash, payment_refund_tx, requested_at, resolved_at, denied_reason }
  • test — sent by the “Send Test” button above.