Connect your server to NairaMove
Use scoped test keys and signed webhooks with delivery history.
Create a read-only test key
Owners can create a named key in Developers. It reads payment status for that business only and expires after 90 days. Keep it on your server. It cannot create payments, refunds or payouts. The secret appears only once. If the creation response is lost, retry to identify the existing key, revoke it and create a replacement.
Receive signed events
Add a public HTTPS endpoint on port 443 and select events. Verify Cashup-Signature with HMAC-SHA256 over the timestamp, a dot and the original request body. Reject stale timestamps and deduplicate using the event ID. Keep signature verification and event handling on your server.
Return a 2xx response within five seconds after durably accepting the event. A payout-created event means a reservation was created; it is not proof of bank settlement.
Handle failures and rotation
Automatic retries wait 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours and 24 hours. Exhaustion pauses the endpoint. Review the recorded attempt status, resume the endpoint and retry exhausted events individually. A resent event keeps its event ID.
Secret rotation provides a 24-hour overlap during which deliveries carry both signatures. Update your receiver before the overlap ends. A request already in flight may finish after pause or disable.
Understand the dashboard
Delivered counts unique events accepted in the last 24 hours. Queued includes waiting and in-flight deliveries. Median response uses recorded HTTP response times, not requests with no response. Delivery history shows the latest 100 events. These are local test capabilities; live integration access is not enabled.
Need help with an issue?