> ## Documentation Index
> Fetch the complete documentation index at: https://baas-api-docs.rexmfbank.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure your webhook

> Sets (or rotates) the URL and signing secret Rex sends event
notifications to. See **[Webhooks Overview](/webhooks/overview)**
and **[Verifying Signatures](/webhooks/signature-verification)**
before going live with this.




## OpenAPI

````yaml /openapi.yaml post /services/partner/webhook
openapi: 3.1.0
info:
  title: Rex Banking-as-a-Service API
  version: 1.0.0
  summary: Embed real bank accounts, transfers, and collections into your product.
  description: |
    The Rex BaaS API lets you provision virtual bank accounts, move money
    between them, accept inbound transfers, and collect at merchant terminals —
    all under your own brand, backed by a real bank ledger.

    This reference covers every endpoint your integration will call. If
    you're just getting started, read **[Getting Started](/introduction)**
    and **[Authentication](/authentication)** first — most integration
    questions are answered there, not in the endpoint list.

    All endpoints are versioned under `/baas/api/v1` and return JSON. See
    **[Errors](/errors)** for the shared error envelope, and
    **[Sandbox vs. Live](/guides/sandbox-vs-live)** for how test and
    production credentials differ.
  contact:
    name: Rex BaaS Support
    email: baas-support@rexmfbank.com
  license:
    name: Proprietary — for approved Rex BaaS partners only
servers:
  - url: https://api.rexmfbank.com/baas/api/v1
    description: Live
  - url: https://sandbox-api.rexmfbank.com/baas/api/v1
    description: Sandbox
security:
  - BearerAuth: []
tags:
  - name: Authentication
    description: Register a partner account, verify it, log in, and manage credentials.
  - name: Onboarding
    description: |
      The one-time KYB (Know Your Business) flow every partner completes
      before going live — business details, a compliance representative,
      supporting documents, and signing the partner agreement.
  - name: Wallet
    description: >-
      Your business's own settlement balance — the account every virtual account
      nets into.
  - name: Virtual Accounts
    description: |
      The core product — dedicated bank account numbers you issue to your
      own end users, with full transfer and transaction capabilities.
  - name: Webhooks
    description: Configure where and how Rex notifies your system of events in real time.
  - name: Partner Settings
    description: >-
      Account security, team members, disputes, and document management for your
      own partner account.
paths:
  /services/partner/webhook:
    post:
      tags:
        - Webhooks
      summary: Configure your webhook
      description: |
        Sets (or rotates) the URL and signing secret Rex sends event
        notifications to. See **[Webhooks Overview](/webhooks/overview)**
        and **[Verifying Signatures](/webhooks/signature-verification)**
        before going live with this.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - url
              properties:
                url:
                  type: string
                  format: uri
                  maxLength: 191
                regenerate_secret:
                  type: boolean
                  default: false
                  description: Rotates the signing secret — do this if it may have leaked.
      responses:
        '200':
          description: |
            `secret` is the plaintext signing secret and is returned **only
            this once** (on first creation, or when `regenerate_secret` is
            true) — every later `GET` returns it masked.
          content:
            application/json:
              example:
                status: success
                message: Webhook configuration saved.
                data:
                  url: https://acme.example/webhooks/rex
                  webhook_alert: true
                  transaction_alert: true
                  secret: whsec_...
                  secret_notice: Store this secret now — it will not be shown again.
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: sk_live_... / sk_sandbox_...
      description: |
        See **[Authentication](/authentication)** for the full explanation
        of session tokens vs. API keys and when each is used.

````