Webhooks overview
How Zaher delivers store events to your endpoints.
A webhook is an HTTP POST that Zaher sends to a URL you own when
something happens in your store. Instead of asking Zaher "anything new?" on a
timer, your system is told the moment it happens.
How it works
- You add an endpoint — an HTTPS URL plus the events it should receive — in Settings → Webhooks. Each endpoint gets its own signing secret.
- When an event happens (say, an order is completed), Zaher stores it and sends it to every enabled endpoint subscribed to that event.
- Each request is signed with the endpoint's secret so you can verify it came from Zaher and wasn't changed.
- Your endpoint replies with any
2xxstatus within 10 seconds. Anything else — an error, a timeout — is retried for about 24 hours.
Every request looks like this
{
"id": "6f1c2b9e-…",
"type": "order.completed",
"api_version": "2026-10-01",
"created_at": "2026-10-01T09:30:00.000Z",
"store_id": "8d4a…",
"test": false,
"data": { "id": "…", "status": "completed", "total": "255.00", "...": "…" }
}typetells you which event it is and therefore the shape ofdata.datais a full snapshot of the resource at the moment of the event.idis the same on every retry of the same event — use it to deduplicate.
Good to know
- At-least-once delivery. You may receive the same event more than once. See Retries and duplicates.
- No ordering guarantee. Events can arrive out of order; use
created_at. - Plans. Webhooks are available on Pro (3 endpoints) and Advanced (10).
- Versioning. Each endpoint is pinned to the
api_versionit was created with. Breaking changes ship as a new version you opt into.