What are Webhooks?
Webhooks are HTTP callbacks that notify your server when events happen in Shoppex — a paid order, a new subscription, a dispute. Instead of polling the API, your server receives events in real time.This page covers normal Shoppex event webhooks.
dynamic_webhook for DYNAMIC products is a separate fulfillment callback contract. See Dynamic Product Delivery.Setting Up Webhooks
Configure webhook endpoints in the Dashboard:1
Open webhook settings
Go to Settings → Webhooks
2
Add a new endpoint
Click Add Endpoint
3
Enter your URL
Enter your endpoint URL
4
Select events
Select which events to receive
Webhook Payload
All webhooks follow this structure:Dashboard test deliveries use the same
event / data / created_at envelope as live deliveries.
The payload values are synthetic examples, but Shoppex signs the raw JSON body the same way as a real delivery.Top-level webhook
created_at is a Unix timestamp.
Nested timestamps inside data can be ISO 8601 strings.Headers
Each webhook request includes these headers:Signature Verification
Always verify webhook signatures to ensure authenticity. New integrations should verifyX-Shoppex-Signature-V2.
Shoppex signs ${deliveryId}.${timestamp}.${rawBody} with HMAC-SHA256.
Your webhook handler should reject timestamps outside a 5-minute window.
Per-payment callbacks created with the
webhook field on POST /dev/v1/payments are different from global webhook endpoints. Their signing secret is returned once as webhook_secret in the payment creation response.Developer webhooks must target your own HTTP(S) endpoint. For Discord notifications, use Notifications → Sales Alerts instead of entering a Discord webhook URL.
Testing Webhooks
Use the dashboard to send test events:1
Open webhook settings
Go to Settings → Webhooks
2
Select your endpoint
Click on your endpoint
3
Send a test event
Click Send Test Event
4
Choose an event type
Select an event type
Test
order:* deliveries include the main live fields you usually integrate against, for example gateway, total, total_display, currency, exchange_rate, crypto_gateway, apm_method, customer_email, and product context.Retry Policy
If your endpoint returns an error (non-2xx status) or times out, Shoppex retries automatically:
After the 5th failed attempt, the webhook is marked as failed. You can manually retry from the dashboard.
Best Practices
Return 200 quickly
Return 200 quickly
Process webhooks asynchronously. Return
200 OK immediately and handle the event in a background job.Handle duplicates
Handle duplicates
Webhooks may be delivered more than once. Use the
X-Shoppex-Delivery header to deduplicate.Verify signatures
Verify signatures
Always verify webhook signatures in production to prevent spoofing.
Use HTTPS
Use HTTPS
Always use HTTPS endpoints in production for security.
Next Steps
Webhook Events
Full list of event types and payload examples
Dynamic Delivery
Deliver digital products in real-time