Build your receiver to answer fast, accept repeats and check what it receives. This page gives the exact delivery rules.
The request
| Property | Value |
|---|
| Method | POST |
| Body | JSON with event and data. See events and payloads |
| Headers | Content-Type: application/json and Signature |
| TLS | The certificate of an https:// address is verified. An invalid certificate fails the delivery |
| Reply time allowed | 3 seconds |
What counts as delivered
Any reply with a 2xx status. Any other final status, a timeout or a failed connection counts as a failure.
Answer with 200 as soon as you have stored the message. Do slow work afterwards.
Retries
| Try | When |
|---|
| 1 | When the event happens |
| 2 | 10 seconds after the first failure |
| 3 | 100 seconds after the second failure |
After the third failure the message is dropped. Nothing records it and nobody is told. The panel has no delivery log and no resend.
Plan for this:
- A retry can deliver the same event twice if your reply was lost. Use the order or return identifier in
data to ignore repeats.
- Events for one order can arrive out of order when an earlier one is being retried.
- To recover from a long outage, read orders again with the incoming orders endpoint.
When nothing is sent
- The webhook is Paused, or the event is not ticked on it.
- Your plan does not include "Webhooks & developer API". Webhooks stay saved and resume when it does.
- The order is a demo-store order, or the return belongs to one.
Each request carries a Signature header. It is the lowercase hexadecimal HMAC-SHA256 of the request body, keyed with a signing secret.
To verify a message:
- Read the raw request body, byte for byte, before any JSON parsing.
- Compute the HMAC-SHA256 of those bytes with your signing secret and write it as lowercase hexadecimal.
- Compare the result with the
Signature header using a constant-time comparison. Reject the message when they differ.
Do not parse the JSON and serialise it again before computing. Any change in spacing or escaping gives a different result.
The panel does not show the signing secret. Ask support for your signing secret.
Good practice for any receiver:
- Use an
https:// address and keep it private.
- Before acting on money or stock, read the order again through the incoming orders endpoint and compare.
- Ignore event names you did not tick.
Testing
Create a webhook that points at a request inspector, tick one event, and trigger it in the shop. The What we send card on the form shows the method, the header name, the reply time and the number of tries.