3.3 Deposit callback
The required callback_url from Create deposit receives a POST when the deposit reaches a terminal v2 result: SUCCESS or FAILED, including a later permitted correction to a different terminal result. Intermediate PENDING states do not generate v2 callbacks.
The payload and signing rules are the same as for the withdrawal callback, with your deposit's order_id:
{"order_id":"DEP-BOB-1001"}
Verify X-Signature over the exact raw body using the API key secret, durably accept the notification, acknowledge with HTTP 200, and handle retries idempotently. HTTP 202/204, redirects, and other non-200 responses are not acknowledgements. The callback does not include the result; use Get deposit status for the current result. A repeated order_id may be a retry or a later correction: refresh status again rather than permanently ignoring the order after its first callback. The shared callback guide covers response timing, key rotation, bounded retries, and delivery ordering.