1. Issuing
PIK
  • Start
    • Getting Started
  • Authentication
    • Authentication Token
      POST
  • Global Account
    • Contacts
      • Create Contact
      • List Contacts
      • Get Contact
      • Count Contacts
    • Virtual Accounts
      • Create Virtual Account
      • List Virtual Accounts
      • Get Virtual Account
    • Transactions
      • List Transactions
      • Get Transaction
    • Account Balance
      • List Account Balances
      • Get Balance by Currency
    • Payout
      • Create Payout
  • Payment Links
    • Payment Links
      • Create Payment Link
      • Update Payment Link
      • Get Payment Link Detail
      • Get Payment Link List
    • Transactions
      • Get Transaction List
  • Issuing
    • Card Products
      • List Card Products
    • Cardholders
      • Create Cardholder
      • List Cardholders
      • Get Cardholder
    • Cards
      • Issue Card
      • List Cards
      • Get Card
      • Create Card Secure Session
      • Adjust Card Limit
      • Freeze Card
      • Unfreeze Card
    • Transactions
      • List Transactions
      • Get Transaction
  • Webhook
    • Global Account
      • Deposit Webhook
      • Payout Webhook
      • Virtual Account Webhook
    • Payment Links
      • Overview
      • Order Collect Out Webhook
      • Customer Payment Webhook
      • Customer Refund Webhook
      • Master Recharge Webhook
      • Web3 Direct Payment Webhook
      • Withdraw Out Webhook
    • Issuing
      • Card Operation Failed
      • Card OTP
      • Card Updated
      • Transaction Completed
      • Transaction Declined
      • Transaction Refunded
      • Transaction Reversed
      • Card Activated
      • Card Failed
  1. Issuing

Transaction Reversed

transaction.reversed — delivered when a reversal's funds are back in your available USD
balance.

When it fires#

When a transaction is reversed and its funds are back in your available USD balance. This covers
both cases:
The original had not posted yet — the hold placed at authorisation is released.
The original had already posted — the debited amount is credited back.
A reversal produces two events for the same transactionNo, and they mean different things:
EventMeaningMoney moved?
transaction.completedThe reversal transaction has postedNot necessarily yet
transaction.reversedThe funds are back in your available balance (hold released or amount credited back)Yes
Returning the money is a separate step from recording the reversal, and it can lag behind. If it
does not succeed the first time it is retried independently, so the gap between the two events is
occasionally minutes rather than milliseconds.
Do not book both as separate movements. Use transaction.completed to learn that a reversal
exists, and this event to learn that the balance has actually changed.

Payload#

Envelope#

FieldTypeDescription
eventIdstringUnique per event. Deduplicate on this value
eventTypestringAlways transaction.reversed
versionstringPayload schema version. Additive changes do not bump it
occurredAtstringWhen the funds were returned (hold released or amount credited back) — not when the reversal posted (ISO 8601)
dataobjectThe reversal transaction, see below

data#

Structurally identical to the response of GET /api/v1/issuing/transaction/{transactionNo}, and
to the data of transaction.completed for the same transaction. One parser handles all paths.
FieldTypeDescription
transactionNostringPIK transaction number of the reversal
originalTransactionNostringThe transaction being reversed
cardNostringPIK card number
cardholderNostringPIK cardholder number
typestringAlways REVERSAL for this event
statusstringCOMPLETED
transactionAmount / transactionCurrencystringAmount and currency at the merchant
billingAmount / billingCurrencystringAmount returned in the card's settlement currency
fxobjectForeign exchange details
feesarrayItemised fee breakdown
totalFeeAmountstringSum of all fee amounts
totalDebitAmountstringbillingAmount + totalFeeAmount
merchantobjectname / mcc / city / country
transactionTime / postedTimestringTransaction and posting times
declineReasonstringnull for this event
See Transaction Completed for the full field reference of fx
and fees[].

Example#

{
  "eventId": "evt_01J9X8ZQ4T9P",
  "eventType": "transaction.reversed",
  "version": "1.0",
  "occurredAt": "2026-09-23T05:41:09Z",
  "data": {
    "transactionNo": "TX260923R4S6T2",
    "originalTransactionNo": "TX260811K3M5N1",
    "cardNo": "CD260811X9Y8Z7",
    "cardholderNo": "CH260811A1B2C3",
    "type": "REVERSAL",
    "status": "COMPLETED",
    "transactionAmount": "40.00",
    "transactionCurrency": "USD",
    "billingAmount": "40.00",
    "billingCurrency": "USD",
    "fx": {
      "isCrossCurrency": false,
      "rate": "1.00000000"
    },
    "fees": [],
    "totalFeeAmount": "0.00",
    "totalDebitAmount": "40.00",
    "merchant": {
      "name": "STEAM PURCHASE",
      "mcc": "5734",
      "city": "Singapore",
      "country": "SG"
    },
    "transactionTime": "2026-09-23T05:40:55Z",
    "postedTime": "2026-09-23T05:40:58Z",
    "declineReason": null
  }
}

Verifying the signature#

Three headers accompany every delivery:
HeaderValue
X-Webhook-EventEvent category, always ISSUING for this event
X-Webhook-Event-TypeThe specific event type, see above
X-Webhook-SignatureHMAC-SHA256 signature, lowercase hex
X-Webhook-Signature = hex_lower( HMAC_SHA256( appSecret, rawBody ) )
The signed content is the raw request body only, with no timestamp and no separator. The signing
key is your appSecret — there is no separate webhook secret.
1.
Sign the raw bytes of the request body, before any JSON parsing.
2.
Compare in constant time.
3.
Nothing time-based is signed, so a captured delivery stays replayable — deduplicating on
eventId is mandatory, not optional
.

Delivery#

Return any 2xx within 10 seconds to acknowledge.
Failed deliveries are retried on a fixed interval: 5 attempts, 5 minutes apart (about
20 minutes in total), after which the event is marked exhausted and never retried again.
This endpoint receives Issuing events only; still return 2xx for event types you do not handle.
Delivery is at least once — deduplicate on eventId.
Ordering is not guaranteed — use occurredAt to decide which version is newer. In particular,
do not assume this event arrives after the matching transaction.completed.
Treat transactionNo as the business key; a transaction generates several events.
See the Webhooks guide for verification code samples and recommended
handling.
Modified at 2026-09-30 09:27:03
Previous
Transaction Refunded
Next
Card Activated
Built with