Z Zise Developers 简体中文

card.application.rejected

Card application execution failed

When Emitted

Triggered after execution failure or an explicit cardholder rejection causes the application to become failed. It does not depend on the member’s email address; repeated execution is deduplicated by application ID and status version. The notification status is rejected, while the application detail status is failed. Raw upstream reasons are not published. Retrieve failure_code from the details to determine how to handle the failure.

Payload

{
  "event_id": "evt_491ad542803841bca106f69ae28a3c14",
  "event_type": "card.application.rejected",
  "created_at": "2026-09-15T08:00:00Z",
  "merchant_id": "acme",
  "livemode": true,
  "data": {
    "object": "card_application",
    "id": "cap_9c41f0a8-27d5-4e63-b0a9-1f7c85d2e340",
    "external_member_id": "u_88123",
    "status": "rejected",
    "status_version": 4
  }
}

Payload Fields

FieldTypeDescription
idstringUse this for deduplication. evt_… remains unchanged when the same event is redelivered.
typestringAlways card.application.rejected
created_atstringTime the event was created (RFC3339), not its delivery time. It is unchanged on redelivery.
data.objectstringObject type; determines which endpoint to query with data.id
data.idstringObject ID; use it to retrieve details.
data.statusstringTreat unrecognized values as unknown and raise an alert; do not fall back to “processing”
data.status_versionnumberMonotonically increasing; use it to discard older states that arrive late.

Signature Verification and Deduplication

Verify the signature against the raw request body bytes. Do not parse and reserialize the JSON: your JSON library may change key order or whitespace, which changes the signature and can look like a key configuration error.

// Node · Run before parsing JSON
const raw = await readRawBody(req);            // Buffer / string; do not use parsed req.body
const expect = crypto.createHmac("sha256", WEBHOOK_SECRET).update(raw).digest("hex");
const got = req.headers["z-signature"];        // Format: t=<unix>,v1=<hex>
if (!timingSafeEqual(expect, parseV1(got))) return res.status(400).end();

// Deduplicate using the envelope id, not data.id
if (await seen(JSON.parse(raw).id)) return res.status(200).end();

For the full procedure, including timestamp tolerance and redelivery semantics, see Webhook Guide.