Webhooks
Signed event delivery, coming with ENGIN-50.
Not available yet
Webhooks come with ENGIN-50. This page describes the plan so you can design for it; details may change before they ship. The SDK’s verifyWebhook() throws until then.
The plan
- Subscriptions for a person, a store or admins: a URL, the events to send, and a signing secret, made where API keys are made, and through the API.
- Signed: each delivery carries a
Collector-Signatureheader, an HMAC-SHA256 of the timestamp and raw body, so you can check it came from us and isn’t a replay. - At least once: failed deliveries are retried with backoff for 24 hours. Each event has an
id: use it to skip duplicates. - A delivery log with each attempt’s status, and a way to resend one or send a test event.
Planned events
collection.item.created, .updated, .deletedwishlist.matchhold.requested, .accepted, .declined, .expired, .completedquestion.asked, .answeredlisting.sold, .out_of_stockmoderation.item.created, .resolvedexport.ready
Next: Barcodes