Set up an endpoint
Each account has one endpoint. Register it withwebhook/set:
secret, which starts with whsec_. Store it now, because it isn’t shown again. Use webhook/rotateSecret to replace it.
The URL must be https://, and private or loopback addresses are refused. Pause delivery with {"enabled": false}.
Delivery
Each event is aPOST with a JSON body:
Reply with any
2xx within 10 seconds. Anything else, including a timeout, is retried after about 1 minute, 5 minutes, 30 minutes, 2 hours and 5 hours. After 6 failed attempts the event is dropped.
An event can arrive more than once, and events can arrive out of order. Use id to drop duplicates, and re-read the object with the API if the order matters.
Verify the signature
The signature is an HMAC-SHA256 of<t>.<raw body>, keyed with your endpoint secret. Always verify it on the raw request body, before parsing it.
Events
Objects in webhook payloads have the same fields as the same objects in API responses.