webhook
card-cancelled
Sent when a card charge ends without payment: the hosted checkout session expired (failure_code is expired or the last decline code), or a direct card API attempt failed after the request returned.
Sent as POST with Content-Type: application/json. There is no signature header; see the Webhooks guide for how to verify. Retries: up to 6 attempts (backoff 30 s, 2 min, 5 min, 15 min, 30 min).
200Return any 2xx to acknowledge. 5xx, 408, 425, 429 and timeouts are retried; other 4xx are not.
