1. Documentation
Image
Vortex
  • Documentation
    • Overview
    • Quick Start With The SDK
    • Authentication And API Keys
    • Ramp Lifecycle
    • Ephemeral Key Custody
    • Quotes And Pricing
    • Webhooks
    • Widget Integration
    • Fiat Corridors
    • Sandbox
    • Production Checklist
    • KYB Deep Link
    • Managed Profiles
    • Custom UI Integration
    • AI Agent Integration
  • API Endpoints
    • Vortex Widget
      • Create widget session
    • Quotes
      • Create a new quote
      • Get existing quote
      • Create a quote for the best network
    • Ramp
      • Get ramp status
      • Get ramp error logs
      • Get ramp history for wallet address
      • Register new ramp process
      • Start ramp process
      • Get authenticated user ramp history
      • Update ramp process
    • Reference Data
      • Supported Countries
      • Supported Cryptocurrencies
      • Supported Fiat Currencies
      • Supported Payment Methods
    • Public Key
      • Public Key
    • Webhooks
      • Register Webhook
      • Delete Webhook
    • Account Management
      • Create user or retry KYC
      • Get user's KYC status
      • Get selfie liveness URL
      • Get KYC document upload URLs
      • Get KYC document upload URLs
      • Get user information
      • Get user's remaining transaction limits
      • Submit KYC level 1 data
      • Validate Pix key
      • Create user or retry KYC
      • Get user's KYC status
      • Get selfie liveness URL
      • Get user information
      • Get user's remaining transaction limits
      • Submit KYC level 1 data
      • Validate PIX key
      • List fiat accounts
      • Create a fiat account
      • Delete a fiat account
      • Get user ramp limits
      • Get sanitized ramp eligibility
    • Authentication
      • List the user's API keys
      • Create a user-linked API key pair
      • Revoke an API key
      • Request an email OTP
      • Verify an email OTP
      • List API credentials
      • Create an API credential
      • Revoke an API credential
    • KYC and KYB
      • Get KYB attempt status
      • Create KYB document
      • Get KYB document
      • Submit API-driven KYB
      • Start hosted KYB
      • Create KYB UBO
      • Import an individual KYC token
      • Record an initial KYC attempt
      • Get customer status
      • Create a business customer
      • Create an individual customer
      • Find KYB submission details
      • Get a KYB redirect link
      • Get a KYC redirect link
      • Get KYC or KYB status
      • Mark a redirect finished
      • Mark a redirect opened
      • Retry KYC or KYB
      • Send a KYB submission
      • Send a KYC submission
      • Upload a KYB file
      • Submit KYB information
      • Upload a related-person KYB file
      • Upload a KYC file
      • Submit KYC information
      • Select active customer entity
      • Discover KYC or KYB requirements
      • Get aggregate onboarding status
    • Managed Profiles
      • List managed profiles
      • Create a managed profile
      • Delete a managed profile
      • Get a managed profile
      • List a managed profile's API credentials
      • Create a managed profile API credential
      • Revoke a managed profile API credential
    • Schemas
      • AccountMeta
      • AveniaDocumentType
      • ApiCredential
      • AveniaKYCDataUploadRequest
      • ApiCredentialErrorResponse
      • AveniaKYCDataUploadResponse
      • ApiCredentialManagedSelectorErrorResponse
      • BrlaAddress
      • ApiValidationErrorResponse
      • BrlaErrorResponse
      • BrAddress
      • BrlaGetSelfieLivenessUrlResponse
      • BrDocumentType
      • BrlaValidatePixKeyResponse
      • BrErrorResponse
      • CleanupPhase
      • BrGetSelfieLivenessUrlResponse
      • CountryCode
      • BrImportKycTokenErrorResponse
      • CreateBestQuoteRequest
      • BrImportKycTokenRequest
      • CreateQuoteRequest
      • BrImportKycTokenResponse
      • BrKYCDataUploadRequest
      • BrKYCDataUploadResponse
      • DestinationType
      • BrKybAttemptStatusResponse
      • BrKybDocumentRequest
      • ErrorResponse
      • BrKybDocumentResponse
      • FiatToken
      • BrKybDocumentUploadResponse
      • BrKybHostedResponse
      • GetRampErrorLogsResponse
      • BrKybLevel1Payload
      • GetRampHistoryResponse
      • BrManagedBadRequestResponse
      • BrUboControlRole
      • BrUboPayload
      • BrUboResponse
      • GetWidgetUrlLocked
      • BrValidatePixKeyResponse
      • GetWidgetUrlRefresh
      • KYCDataUploadFileFiles
      • KYCDocType
      • CreateApiCredentialRequest
      • KycLevel1Payload
      • CreateApiCredentialResponse
      • KycLevel1Response
      • ListUserApiKeysResponse
      • CreateManagedProfileRequest
      • Networks
      • CreateSubaccountRequest
      • OnChainToken
      • CreateSubaccountResponse
      • PaymentData
      • PaymentMethod
      • DocumentUploadEntry
      • PresignedTx
      • QuoteResponse
      • DomesticAddFiatAccountRequest
      • RampCurrency
      • DomesticCountry
      • RampDirection
      • DomesticCountryAndCustomerTypeRequest
      • RampErrorLog
      • DomesticCountryRequest
      • RampPhase
      • DomesticCreateCustomerRequest
      • RampProcess
      • DomesticCreateCustomerResponse
      • RegisterRampRequest
      • DomesticCreateFiatAccountResponse
      • SimpleStatus
      • DomesticCustomerType
      • StartKYC2Request
      • DomesticErrorResponse
      • StartKYC2Response
      • DomesticFiatAccount
      • StartRampRequest
      • DomesticFiatAccountType
      • TaxIdType
      • DomesticKybBusinessSummary
      • TriggerOfframpRequest
      • DomesticKybDetailsResponse
      • TriggerOfframpResponse
      • DomesticKybFileUploadRequest
      • UnsignedTx
      • DomesticKybRelatedPerson
      • DomesticKybRelatedPersonFileUploadRequest
      • UserApiKeyErrorResponse
      • DomesticKycFileUploadRequest
      • UserApiKeyPairResponse
      • DomesticKycStatusResponse
      • ValidatePixKeyResponse
      • DomesticManagedBadRequestResponse
      • DomesticRedirectLinkResponse
      • DomesticRedirectNotificationRequest
      • DomesticRelatedPersonFileUploadRequest
      • DomesticRetryRequest
      • DomesticRetryResponse
      • DomesticSendSubmissionRequest
      • DomesticStatus
      • DomesticStatusResponse
      • DomesticSubmissionResponse
      • DomesticSubmitKybInformationRequest
      • DomesticSubmitKycInformationRequest
      • DomesticSuccessResponse
      • DomesticValidationBadRequestResponse
      • ErrorManagedSelectorResponse
      • FlatErrorResponse
      • FlatManagedSelectorErrorResponse
      • GetKycStatusResponse
      • GetRampHistoryTransaction
      • GetUserLimitsRequest
      • GetUserLimitsResponse
      • GetUserRemainingLimitResponse
      • GetUserResponse
      • KybAttemptStatusResponse
      • KybLevel1Response
      • ListApiCredentialsResponse
      • ListManagedProfilesResponse
      • MalformedJsonErrorResponse
      • LivenessDocumentEntry
      • ManagedProfile
      • ManagedProfileErrorResponse
      • ManagedProfilePagination
      • ManagedProfileResponse
      • ManagedProfileManagerPolicy
      • ManagedSelectorErrorResponse
      • OnboardingApiErrorResponse
      • OnboardingDocumentRequirement
      • OnboardingRequirementStep
      • OnboardingRequirementsErrorResponse
      • OnboardingRequirementsResponse
      • OnboardingStatusErrorResponse
      • OnboardingStatusResponse
      • PayloadTooLargeErrorResponse
      • RampInfoResponse
      • RecordInitialKycAttemptRequest
      • SelectActiveCustomerEntityRequest
      • SelectActiveCustomerEntityResponse
      • SubmitInformationResponse
      • SubmitKybInformationRequest
      • SubmitKycInformationRequest
      • SuccessResponse
      • UpdateRampRequest
      • UserLimit
      • UserLimitPeriod
  1. Documentation

Webhooks

Vortex webhooks let your application receive real-time notifications when ramp lifecycle events occur, instead of continuously polling GET /v1/ramp/{id}.
You can subscribe to:
Transaction creation — a new ramp is registered.
Status changes — a ramp's status moves between PENDING, COMPLETE, and FAILED.

Security Model#

Every webhook request includes:
X-Vortex-Signature — RSA-PSS signature of the raw request body, base64-encoded.
X-Vortex-Timestamp — Unix timestamp (seconds) of the request.
All webhook URLs must use HTTPS. Signatures are verified against the RSA-PSS 2048-bit public key returned by GET /v1/public-key.

Registering A Webhook#

{
  "url": "https://partner.example.com/vortex/webhook",
  "quoteId": "quote_...",
  "events": ["TRANSACTION_CREATED", "STATUS_CHANGE"]
}
The body must include exactly one of quoteId or sessionId. Use sessionId to subscribe to events from a Widget-hosted ramp instead of a partner-created quote.
Store the returned webhook ID so you can delete it later.
Webhook endpoints require a partner secret key. They do not accept Supabase Bearer tokens.

Event Types#

TRANSACTION_CREATED#

Fired immediately after the ramp state is created (POST /v1/ramp/register).
{
  "eventType": "TRANSACTION_CREATED",
  "timestamp": "2025-01-15T10:30:00.000Z",
  "payload": {
    "quoteId": "quote_...",
    "transactionId": "tx_...",
    "sessionId": "session_...",
    "transactionStatus": "PENDING",
    "transactionType": "BUY"
  }
}
FieldDescription
quoteIdUnique identifier for the quote.
transactionIdUnique identifier for the ramp (rampId).
sessionIdWidget session identifier if registered against a session.
transactionStatusAlways "PENDING" for new transactions.
transactionType"BUY" (onramp) or "SELL" (offramp).

STATUS_CHANGE#

Fired whenever the ramp's status changes during processing.
{
  "eventType": "STATUS_CHANGE",
  "timestamp": "2025-01-15T10:35:00.000Z",
  "payload": {
    "quoteId": "quote_...",
    "transactionId": "tx_...",
    "sessionId": "session_...",
    "transactionStatus": "COMPLETE",
    "transactionType": "BUY"
  }
}
Status values:
PENDING — ramp is in progress.
COMPLETE — ramp completed successfully.
FAILED — ramp failed or timed out.

Retry Mechanism#

Vortex automatically retries failed webhook deliveries:
Attempts: up to 5
Backoff: exponential (1s, 2s, 4s, 8s, 16s)
Timeout: 30 seconds per request
Auto-deactivation: after 5 consecutive failures, the webhook is disabled and must be re-registered.
Return 2xx quickly. Do heavy work asynchronously after acknowledging the request.

Verification#

Fetch the current public key:
Verify signatures using RSA-PSS with SHA-256. Reject requests that fail signature verification, are outside an acceptable timestamp window, contain malformed payloads, or do not match the expected event structure.

Example: Bun + TypeScript Listener#

When To Still Poll#

Webhooks are preferable for reconciliation, back-office automation, and support workflows. Polling GET /v1/ramp/{id} is still useful for live user-facing status screens where you want sub-second updates without waiting for the next webhook delivery. GET /v1/ramp/{id}/errors returns the structured error log and is useful for support tooling.

Modified at 2026-05-19 08:03:57
Previous
Quotes And Pricing
Next
Widget Integration
Built with
Advertisement
Advertisement