Skip to main content
Webhooks send an HTTP POST to your server when something happens in your store, so you don’t have to poll. Create endpoints in Developers › Webhooks or with POST /webhooks.

Events

GET /events/types returns the same list.

Payload

Webhook amounts are in major units (34.99), unlike the API, which uses minor units (3499).

Verify the signature

Every request has these headers: The signature is HMAC-SHA256(secret, "<t>.<raw body>") in hex. The secret (whsec_...) is shown when you create the endpoint. Compute it over the raw body, before parsing JSON, and reject old timestamps.

Respond and retries

  • Answer with any 2xx status within 10 seconds. Do slow work after you respond.
  • Failed deliveries are retried after 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours and 12 hours (7 attempts over about 21 hours).
  • An endpoint is turned off after 40 failures in a row with no success in 3 days. Turn it back on in the dashboard or with PATCH /webhooks/{id} and enabled: true.
  • The same event can arrive more than once. Use PapelShip-Event-Id to process it once.

Manage endpoints with the API

The response contains the signing secret. It is shown only once; store it in your server’s environment. Rolling the secret stays in the dashboard.