How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

PayPal Verify-Webhook-Signature API

Use the `/verify-webhook-signature` resource to verify a webhook signature.

PayPal Verify-Webhook-Signature API is one of 27 APIs that PayPal publishes on the APIs.io network, described by a machine-readable OpenAPI specification and an AsyncAPI event-driven specification.

Tagged areas include Verify-Webhook-Signature. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an AsyncAPI specification.

This API exposes 1 operation across 1 path, and defines 8 schemas. It is described by OpenAPI 3.2.0, at version 1.11.

Requests are made against 2 base URLs: https://api-m.sandbox.paypal.com, https://api-m.paypal.com.

1 operations 1 paths 8 schemas 1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.11
Servers
https://api-m.sandbox.paypal.com
https://api-m.paypal.com
Authentication
OAuth 2.0
Resource Areas
1

Authentication & Security 1

PayPal Verify-Webhook-Signature API declares 1 security scheme for authenticating requests. It supports OAuth 2.0 (Oauth2) using the clientCredentials flow, exposing 2 scopes.

  • Oauth2 — Oauth 2.0 authentication

Paths & Operations 1

Across 1 path, the API surfaces 1 operation — 1 POST. Each is listed below with its method, path, parameters, and response codes.

Verify-Webhook-Signature 1

Use the /verify-webhook-signature resource to verify a webhook signature.

POST
/v1/notifications/verify-webhook-signature
Paypal Verify webhook signature
verify-webhook-signature.post body → 200default

Schemas 8

The contract defines 8 schemas that model the data the API accepts and returns. The most detailed are event (9 properties), verify_webhook_signature (7 properties), error (6 properties), error_details-2 (5 properties). Each schema is shown below with its type and property counts.

event
object
A webhook event notification.
9 properties
event_version
string
The event version in the webhook notification.
error
object
The error details.
6 properties 3 required
verify_webhook_signature_response
object
The verify webhook signature response.
1 property 1 required
verify_webhook_signature
object
A verify webhook signature request.
7 properties 7 required
resource_version
string
The resource version in the webhook notification.
error_details-2
object
The error details. Required for client-side 4XX errors.
5 properties 1 required
link_description
object
The request-related [HATEOAS link](/docs/api/reference/api-responses/hateoas-links) information.
3 properties 2 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

paypal-verify-webhook-signature-api-openapi.yml Raw ↑

Other APIs PayPal publishes across the network.

PayPal Authorizations API
PayPal Balances API
PayPal Billing API
PayPal Captures API
PayPal Disputes-Actions API
PayPal Disputes API
PayPal Invoices API
PayPal Orders API
PayPal Partner-Referrals API
PayPal Payment-Tokens API
PayPal Payouts API
PayPal Payouts-Item API
Where this information came from

This is an independent, third-party profile of PayPal Verify-Webhook-Signature API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.