openapi: 3.0.0 info: title: Razorpay Bills Partner Webhooks API version: 1.0.0 description: Razorpay payment gateway APIs for accepting payments, managing orders, processing refunds, payouts, and subscriptions. All amounts are in the smallest currency sub-unit (e.g. paise for INR). Supports 180+ payment methods including UPI, cards, netbanking, wallets, and EMI. termsOfService: https://razorpay.com/terms/ contact: name: Razorpay Support url: https://razorpay.com/support/ email: support@razorpay.com license: name: Proprietary url: https://razorpay.com/terms/ x-logo: url: https://razorpay.com/favicon.png x-auth-environments: test: keyPrefix: rzp_test_ description: Test mode — keys prefixed rzp_test_. Same API endpoint (https://api.razorpay.com/v1). No real money movement. Use test card numbers from https://razorpay.com/docs/payments/payments/test-card-details/. live: keyPrefix: rzp_live_ description: Live mode — keys prefixed rzp_live_. Real money movement. Requires KYC and business activation on the Razorpay Dashboard. servers: - url: https://api.razorpay.com/v1 description: Production security: - basicAuth: [] - oauth2: - read_only tags: - name: Partner Webhooks description: Configure webhooks for sub-merchant accounts to receive payment events. Maximum 30 per account. paths: /v2/accounts/{account_id}/webhooks: post: operationId: createPartnerWebhook summary: Create a webhook for a sub-merchant description: 'Create a webhook to receive events for a sub-merchant account. Maximum 30 webhooks per account. Authentication: OAuth access_token.' tags: - Partner Webhooks security: - basicAuth: [] parameters: - name: account_id in: path required: true schema: type: string description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`). requestBody: required: true content: application/json: schema: type: object required: - url - events properties: url: type: string alert_email: type: string secret: type: string active: type: boolean events: type: object additionalProperties: type: boolean responses: '200': description: Webhook created content: application/json: schema: $ref: '#/components/schemas/PartnerWebhook' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' get: operationId: listPartnerWebhooks summary: List webhooks for a sub-merchant description: 'Retrieve all webhooks configured for a sub-merchant account. Authentication: OAuth access_token.' tags: - Partner Webhooks security: - basicAuth: [] parameters: - name: account_id in: path required: true schema: type: string description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`). responses: '200': description: List of webhooks content: application/json: schema: type: object properties: entity: type: string count: type: integer items: type: array items: $ref: '#/components/schemas/PartnerWebhook' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' /v2/accounts/{account_id}/webhooks/{webhook_id}: get: operationId: fetchPartnerWebhook summary: Fetch a webhook by ID description: 'Retrieve details of a specific webhook for a sub-merchant account. Authentication: OAuth access_token.' tags: - Partner Webhooks security: - basicAuth: [] parameters: - name: account_id in: path required: true schema: type: string description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`). - name: webhook_id in: path required: true schema: type: string description: Unique identifier of the webhook (e.g. `we_00000000000001`). responses: '200': description: Webhook details content: application/json: schema: $ref: '#/components/schemas/PartnerWebhook' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' '404': $ref: '#/components/responses/404' patch: operationId: updatePartnerWebhook summary: Update a webhook description: 'Update webhook URL, events, secret, or active status for a sub-merchant account. Authentication: OAuth access_token.' tags: - Partner Webhooks security: - basicAuth: [] parameters: - name: account_id in: path required: true schema: type: string description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`). - name: webhook_id in: path required: true schema: type: string description: Unique identifier of the webhook (e.g. `we_00000000000001`). requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PartnerWebhook' responses: '200': description: Webhook updated content: application/json: schema: $ref: '#/components/schemas/PartnerWebhook' '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' delete: operationId: deletePartnerWebhook summary: Delete a webhook description: 'Delete a webhook for a sub-merchant account. Returns empty array on success. Authentication: OAuth access_token.' tags: - Partner Webhooks security: - basicAuth: [] parameters: - name: account_id in: path required: true schema: type: string description: Unique identifier of the linked merchant account (e.g. `acc_00000000000001`). - name: webhook_id in: path required: true schema: type: string description: Unique identifier of the webhook (e.g. `we_00000000000001`). responses: '200': description: Webhook deleted content: application/json: schema: type: object description: Empty object on success. '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' '404': $ref: '#/components/responses/404' components: responses: '404': description: Resource not found. content: application/json: schema: $ref: '#/components/schemas/Error' '400': description: Bad request. Invalid parameters or missing required fields. content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Authentication failed. Invalid or missing API key credentials. content: application/json: schema: $ref: '#/components/schemas/Error' '500': description: Internal server error. content: application/json: schema: $ref: '#/components/schemas/Error' '429': description: Rate limit exceeded. Implement exponential backoff with jitter before retrying. content: application/json: schema: $ref: '#/components/schemas/Error' schemas: PartnerWebhook: type: object description: A webhook configured for a sub-merchant account via the Partners API. Maximum 30 webhooks per account. properties: id: type: string description: Webhook ID, max 14 characters entity: type: string enum: - webhook owner_id: type: string owner_type: type: string url: type: string description: HTTPS URL to receive webhook events alert_email: type: string secret: type: string description: Shared secret for HMAC verification (write-only) secret_exists: type: boolean active: type: boolean events: type: object additionalProperties: type: boolean description: Map of event names to boolean service: type: string context: type: array items: type: string disabled_at: type: integer created_at: type: integer updated_at: type: integer Error: type: object properties: error: type: object properties: code: type: string description: 'Error code. Examples: BAD_REQUEST_ERROR, GATEWAY_ERROR, SERVER_ERROR.' description: type: string source: type: string description: Where the error originated (e.g. business, gateway). step: type: string reason: type: string description: 'Machine-readable reason. Examples: insufficient_funds, invalid_expiry_date, declined_by_bank.' metadata: type: object field: type: string securitySchemes: basicAuth: type: http scheme: basic description: HTTP Basic authentication using your Razorpay API key pair. Use key_id as the username and key_secret as the password. Encode as Base64(key_id:key_secret). Keys are environment-scoped (Test vs Live). Obtain keys at https://dashboard.razorpay.com/app/keys. Keys are case-sensitive. oauth2: type: oauth2 description: OAuth 2.0 via the Razorpay MCP server (mcp.razorpay.com). Supports Authorization Code with PKCE (S256) for user-delegated access and Client Credentials for server-to-server access. Tokens expire in 3600 seconds. Dynamic Client Registration available at the registration endpoint. For integration setup see https://razorpay.com/docs/build/llm-docs/mcp-server/oauth.md. flows: authorizationCode: authorizationUrl: https://mcp.razorpay.com/authorize tokenUrl: https://mcp.razorpay.com/token refreshUrl: https://mcp.razorpay.com/token scopes: read_only: Read-only access to Razorpay account data (payments, orders, refunds, payouts, subscriptions, invoices) clientCredentials: tokenUrl: https://mcp.razorpay.com/token scopes: read_only: Read-only access to Razorpay account data (payments, orders, refunds, payouts, subscriptions, invoices) externalDocs: description: Razorpay API Documentation url: https://razorpay.com/docs/api/ x-tagGroups: - name: Core Payments tags: - Orders - Payments - Refunds - Payment Downtimes - name: Payment Collection tags: - Payment Links - QR Codes - name: Billing & Subscriptions tags: - Items - Invoices - Plans - Subscriptions - name: Customer Management tags: - Customers - Documents - name: Finance & Reconciliation tags: - Settlements - Instant Settlements - Disputes - name: Route & Marketplace tags: - Linked Accounts - Transfers - name: Smart Collect tags: - Virtual Accounts - name: Partners & Onboarding tags: - Partner Accounts - Partner Products - Partner Stakeholders - Partner Documents - Partner Webhooks - name: Bills tags: - Bills - name: RazorpayX tags: - X Contacts - X Fund Accounts - X Account Validation - X Banking Balances - X Payouts - X Payout Links - X Transactions x-rateLimit: description: Razorpay does not publish specific rate limits. If you receive HTTP 429, implement exponential backoff with jitter and retry. Add randomisation to avoid thundering-herd effects. throttleStatus: 429 strategy: exponential backoff with jitter x-pagination: description: All list endpoints return at most 100 records per call (1000 for settlement recon). Use count and skip together to paginate. Date range filters (from/to) use Unix timestamps in seconds. example: GET /payments?from=1700000000&to=1700086400&count=100&skip=100 x-amountEncoding: description: 'All monetary amounts are in the smallest currency sub-unit. For INR: 1 rupee = 100 paise, so ₹500 = 50000. Minimum for INR is 100 paise (₹1). Three-decimal currencies (KWD, BHD, OMR): drop last decimal digit. Zero-decimal currencies (JPY): pass value as-is.'