This is the inbound callback API. For the full delivery flow (headers, HMAC, payloads) see Callback delivery.
Base URL
https://sandbox-api.opencard.io/api
Auth
X-Data-Signature header — HMAC-SHA256 of the raw request body with your client secret.
Reference for the inbound receipt provider callback API — POST matched receipt payloads to OpenCard with HMAC-SHA256 signatures on api.opencard.io.
https://sandbox-api.opencard.io/api
X-Data-Signature header — HMAC-SHA256 of the raw request body with your client secret.