Skip to main content

What are Webhooks?

Webhooks are HTTP callbacks that notify your server when events happen in Shoppex — a paid order, a new subscription, a dispute. Instead of polling the API, your server receives events in real time.
This page covers normal Shoppex event webhooks. dynamic_webhook for DYNAMIC products is a separate fulfillment callback contract. See Dynamic Product Delivery.

Setting Up Webhooks

Configure webhook endpoints in the Dashboard:
1

Open webhook settings

Go to Settings → Webhooks
2

Add a new endpoint

Click Add Endpoint
3

Enter your URL

Enter your endpoint URL
4

Select events

Select which events to receive
For local development, use a tunnel service like ngrok to expose your local server.

Webhook Payload

All webhooks follow this structure:
Dashboard test deliveries use the same event / data / created_at envelope as live deliveries. The payload values are synthetic examples, but Shoppex signs the raw JSON body the same way as a real delivery.
Top-level webhook created_at is a Unix timestamp. Nested timestamps inside data can be ISO 8601 strings.

Headers

Each webhook request includes these headers:

Signature Verification

Always verify webhook signatures to ensure authenticity. New integrations should verify X-Shoppex-Signature-V2. Shoppex signs ${deliveryId}.${timestamp}.${rawBody} with HMAC-SHA256. Your webhook handler should reject timestamps outside a 5-minute window.
X-Shoppex-Signature and X-Shoppex-Unescaped-Signature are legacy body-only HMAC-SHA512 headers. They remain available during the migration period, but new integrations should use X-Shoppex-Signature-V2.
Your webhook secret is available in Settings → Webhooks in the Dashboard. Keep it secure and never expose it in client-side code.
Per-payment callbacks created with the webhook field on POST /dev/v1/payments are different from global webhook endpoints. Their signing secret is returned once as webhook_secret in the payment creation response.
Developer webhooks must target your own HTTP(S) endpoint. For Discord notifications, use Notifications → Sales Alerts instead of entering a Discord webhook URL.

Testing Webhooks

Use the dashboard to send test events:
1

Open webhook settings

Go to Settings → Webhooks
2

Select your endpoint

Click on your endpoint
3

Send a test event

Click Send Test Event
4

Choose an event type

Select an event type
Test order:* deliveries include the main live fields you usually integrate against, for example gateway, total, total_display, currency, exchange_rate, crypto_gateway, apm_method, customer_email, and product context.
For local development:

Retry Policy

If your endpoint returns an error (non-2xx status) or times out, Shoppex retries automatically: After the 5th failed attempt, the webhook is marked as failed. You can manually retry from the dashboard.
Your endpoint must respond within 30 seconds or the request will timeout and count as a failure.

Best Practices

Process webhooks asynchronously. Return 200 OK immediately and handle the event in a background job.
Webhooks may be delivered more than once. Use the X-Shoppex-Delivery header to deduplicate.
Always verify webhook signatures in production to prevent spoofing.
Always use HTTPS endpoints in production for security.

Next Steps

Webhook Events

Full list of event types and payload examples

Dynamic Delivery

Deliver digital products in real-time