Skip to content

feat: add tikkie-webhooks skill - #213

Merged
garethx merged 2 commits into
hookdeck:mainfrom
garethx:feat/tikkie-webhooks
Oct 8, 2026
Merged

garethx merged 2 commits into
hookdeck:mainfrom
garethx:feat/tikkie-webhooks

Conversation

@garethx

@garethx garethx commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Adds tikkie-webhooks for Tikkie API v2 (ABN AMRO): payment-request and transaction-bundle notifications.

Scheme note: no signature (intentional)

Tikkie notifications are unsigned. The official OpenAPI spec (TikkieAPI_v2.3.yaml) defines only a JSON body and a 2XX ack for the notification callbacks. It has no signature header, no secret and no HMAC. This matches Hookdeck core: the TIKKIE source type has no verification controller (the commit that added it says the webhooks "carry no signature"). Please don't add an HMAC verifier in review.

What the handlers do instead:

  1. Check subscriptionId against the id returned (201) by POST /paymentrequestssubscription / /transactionssubscription. This is a weak check, and the code says so.
  2. Treat the notification as a trigger and re-fetch the authoritative record with API-Key + X-App-Token (getPayment, getRefund, getBundle). The payload has tokens only: no amount and no status.
  3. Dispatch on notificationType: PAYMENT, REFUND, BUNDLE. Payload examples are verbatim from the spec.

Retries ("maximum of three attempts", best-effort) are quoted from the spec.

Testing

  • validate-provider.sh tikkie-webhooks passes
  • Express 22/22, Next.js 20/20, FastAPI 20/20. The re-fetch is mocked, so the tests make no network calls.
  • No live account, so there's no end-to-end delivery test.

🤖 Generated with Claude Code

garethx and others added 2 commits October 8, 2026 09:46
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@garethx
garethx marked this pull request as ready for review October 8, 2026 09:21
@garethx
garethx merged commit 80fea2c into hookdeck:main Oct 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant