Skip to main content
Webhooks notify your server when something changes, so you don’t have to poll.

Set up an endpoint

Each account has one endpoint. Register it with webhook/set:
The first response includes secret, which starts with whsec_. Store it now, because it isn’t shown again. Use webhook/rotateSecret to replace it. The URL must be https://, and private or loopback addresses are refused. Pause delivery with {"enabled": false}.

Delivery

Each event is a POST with a JSON body:
The request has these headers: Reply with any 2xx within 10 seconds. Anything else, including a timeout, is retried after about 1 minute, 5 minutes, 30 minutes, 2 hours and 5 hours. After 6 failed attempts the event is dropped. An event can arrive more than once, and events can arrive out of order. Use id to drop duplicates, and re-read the object with the API if the order matters.

Verify the signature

The signature is an HMAC-SHA256 of <t>.<raw body>, keyed with your endpoint secret. Always verify it on the raw request body, before parsing it.
The timestamp check, five minutes in these examples, protects you from replayed requests.

Events

Objects in webhook payloads have the same fields as the same objects in API responses.