Skip to main content
All routes require:
Paths are store-scoped. The key must include webhook:read, webhook:write, or webhook:delete and access to that shop. Dashboard permission ceilings still apply (manageSettings). These endpoints manage outgoing MARKT events. They are not payment-provider IPN.

List

Scope: webhook:read
The signing secret is never returned on list or get.

Create

Scope: webhook:write
201 includes secret (whsec_…) once. HTTPS is required in production. Local http://127.0.0.1 is allowed only outside production.

Get / update / delete

Scopes: webhook:read / webhook:write / webhook:delete PATCH body (any subset):

Rotate secret

Scope: webhook:write Returns a new secret once. Previous signatures stop verifying.

Test ping

Scope: webhook:write Sends webhook.test immediately. Disabled endpoints return 400.

Delivery log

Scope: webhook:read
Statuses: pending, success, failed, queued, skipped.

Signature (receiver)

See Outgoing webhooks for Node verification.

Errors