POST to your server when something happens in your store, so you don’t have to poll.
Create endpoints in Developers › Webhooks or with POST /webhooks.
Events
GET /events/types returns the same list.
Payload
Webhook amounts are in major units (
34.99), unlike the API, which uses minor units (3499).Verify the signature
Every request has these headers:
The signature is
HMAC-SHA256(secret, "<t>.<raw body>") in hex. The secret (whsec_...) is shown when you create the endpoint. Compute it over the raw body, before parsing JSON, and reject old timestamps.
Respond and retries
- Answer with any
2xxstatus within 10 seconds. Do slow work after you respond. - Failed deliveries are retried after 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours and 12 hours (7 attempts over about 21 hours).
- An endpoint is turned off after 40 failures in a row with no success in 3 days. Turn it back on in the dashboard or with
PATCH /webhooks/{id}andenabled: true. - The same event can arrive more than once. Use
PapelShip-Event-Idto process it once.
Manage endpoints with the API
secret. It is shown only once; store it in your server’s environment.
Rolling the secret stays in the dashboard.