webhook:read, webhook:write, or webhook:delete and access to that shop. Dashboard permission ceilings still apply (manageSettings).
These endpoints manage outgoing MARKT events. They are not payment-provider IPN.
List
webhook:read
Create
webhook:write
201 includes secret (whsec_…) once. HTTPS is required in production. Local http://127.0.0.1 is allowed only outside production.
Get / update / delete
webhook:read / webhook:write / webhook:delete
PATCH body (any subset):
Rotate secret
webhook:write
Returns a new secret once. Previous signatures stop verifying.
Test ping
webhook:write
Sends webhook.test immediately. Disabled endpoints return 400.
Delivery log
webhook:read
pending, success, failed, queued, skipped.