Z Zise Developers 简体中文

remittance.order.action_required

Member action required: confirm a new price or provide supplementary documents

When Emitted

Two situations share this event: exchange-rate movement beyond the member’s chosen limit requires reconfirmation, or the upstream requests supplementary documents. Both have deadlines: missing the reconfirmation deadline automatically cancels the order and returns locked funds; if documents are not supplied, the order remains stalled and the funds stay locked. Direct the member to the order immediately and retrieve GET /v1/remittances/rmt_<id>/pending-action to determine what they must do. The event body does not distinguish these two situations.

Payload

{
  "event_id": "evt_74b0d3e18f6a4c29ba51e07d962f4c83",
  "event_type": "remittance.order.action_required",
  "created_at": "2026-08-12T14:12:19Z",
  "merchant_id": "acme",
  "livemode": true,
  "data": {
    "object": "remittance",
    "id": "1c0e8a37-45bd-4f6a-b2e1-90a7d3f5c862",
    "external_member_id": "u_88123",
    "status": "action_required",
    "status_version": 3
  }
}

Payload Fields

FieldTypeDescription
idstringUse this for deduplication. evt_… remains unchanged when the same event is redelivered.
typestringAlways remittance.order.action_required
created_atstringTime the event was created (RFC3339), not its delivery time. It is unchanged on redelivery.
data.objectstringObject type; determines which endpoint to query with data.id
data.idstringObject ID; use it to retrieve details.
data.statusstringTreat unrecognized values as unknown and raise an alert; do not fall back to “processing”
data.status_versionnumberMonotonically increasing; use it to discard older states that arrive late.

Signature Verification and Deduplication

Verify the signature against the raw request body bytes. Do not parse and reserialize the JSON: your JSON library may change key order or whitespace, which changes the signature and can look like a key configuration error.

// Node · Run before parsing JSON
const raw = await readRawBody(req);            // Buffer / string; do not use parsed req.body
const expect = crypto.createHmac("sha256", WEBHOOK_SECRET).update(raw).digest("hex");
const got = req.headers["z-signature"];        // Format: t=<unix>,v1=<hex>
if (!timingSafeEqual(expect, parseV1(got))) return res.status(400).end();

// Deduplicate using the envelope id, not data.id
if (await seen(JSON.parse(raw).id)) return res.status(200).end();

For the full procedure, including timestamp tolerance and redelivery semantics, see Webhook Guide.