Skip to main content
WEBHOOK

Headers

X-CE-Event
string
required

Event name; equals the body event.

X-CE-Signature
string
required

sha256= followed by the hex HMAC-SHA256 of the raw request body, keyed with the webhook secret. Verify with a constant-time comparison before processing.

Pattern: ^sha256=[0-9a-f]{64}$
X-CE-Event-ID
string
required

Equals the body event_id. Stable across retries — use as the idempotency key.

X-CE-Delivery-ID
string
required

Equals the body delivery_id. Unique per delivery attempt.

Body

application/json

Body of every webhook request. The HMAC-SHA256 signature in X-CE-Signature is computed over the raw request body with the webhook secret. Use event_id as the idempotency key: retries of the same event reuse it while delivery_id changes per attempt.

event
enum<string>
required

Event name, e.g. order.created. Also sent as the X-CE-Event header.

Available options:
payment.retried
event_id
string
required

ULID shared by every delivery attempt of the same event. Also sent as X-CE-Event-ID.

delivery_id
string
required

ULID unique to this delivery attempt. Also sent as X-CE-Delivery-ID.

timestamp
string<date-time>
required

Time this delivery attempt was made.

is_test
boolean
required

true when sent from the admin Send test webhook action.

payload
WebhookPayload · object
required

The inner event record. properties carries the event-specific model documented on each webhook; every other key is common to all events.

Response

Bad request

message
string
required
success
boolean
required
code
string
required
errors
object