Events
A
webhook.test ping is sent only from Send test. It is not a production event.
Dashboard
On Account → Developers:- Create, edit, enable/disable, rotate, and delete endpoints
- Choose events per webhook
- Inspect delivery logs (status, HTTP code, attempt, error)
- Copy the signing secret once at create or rotate
Signature
Every POST includes:${t}.${rawBody} using the signing secret (whsec_…). Reject timestamps older than 5 minutes. Treat deliveries as at-least-once.
Envelope
data is the merchant-safe order or product payload (no payment-provider secrets, no IP intelligence).
Retries
Failed deliveries (network error or non-2xx) retry with exponential backoff (about 1m → 5m → 30m → 2h → 6h). After 10 consecutive failures the webhook is auto-disabled. Re-enable it from Developers after you fix the endpoint. Retries are processed by:Node example
cURL (create via Merchant API)
secret from the 201 body. Later GET responses never include it.