Developers

Webhooks overview

How Zaher delivers store events to your endpoints.

A webhook is an HTTP POST that Zaher sends to a URL you own when something happens in your store. Instead of asking Zaher "anything new?" on a timer, your system is told the moment it happens.

How it works

  1. You add an endpoint — an HTTPS URL plus the events it should receive — in Settings → Webhooks. Each endpoint gets its own signing secret.
  2. When an event happens (say, an order is completed), Zaher stores it and sends it to every enabled endpoint subscribed to that event.
  3. Each request is signed with the endpoint's secret so you can verify it came from Zaher and wasn't changed.
  4. Your endpoint replies with any 2xx status within 10 seconds. Anything else — an error, a timeout — is retried for about 24 hours.

Every request looks like this

{
  "id": "6f1c2b9e-…",
  "type": "order.completed",
  "api_version": "2026-10-01",
  "created_at": "2026-10-01T09:30:00.000Z",
  "store_id": "8d4a…",
  "test": false,
  "data": { "id": "…", "status": "completed", "total": "255.00", "...": "…" }
}
  • type tells you which event it is and therefore the shape of data.
  • data is a full snapshot of the resource at the moment of the event.
  • id is the same on every retry of the same event — use it to deduplicate.

Good to know

  • At-least-once delivery. You may receive the same event more than once. See Retries and duplicates.
  • No ordering guarantee. Events can arrive out of order; use created_at.
  • Plans. Webhooks are available on Pro (3 endpoints) and Advanced (10).
  • Versioning. Each endpoint is pinned to the api_version it was created with. Breaking changes ship as a new version you opt into.

On this page