order.completed
An order was paid and completed.
X-Zaher-Signature*stringv1=<hex> — HMAC-SHA256 of {timestamp}.{raw body} with your endpoint's signing secret. During a secret rotation, two comma-separated values are sent.
X-Zaher-Timestamp*stringUnix seconds when the request was signed. Reject requests older than 5 minutes.
X-Zaher-Event-Id*stringSame as the body id. Use it to deduplicate retries.
X-Zaher-Event-Type*stringSame as the body type.
application/json- body
id*stringEvent id. The same on every retry — use it to deduplicate.
type*"order.completed"Event type
Value in
"order.completed"api_version*stringPayload version pinned on the endpoint
created_at*stringWhen the event happened
store_id*stringThe store the event belongs to
test*booleanTrue for events sent with "Send test event"
data*Acknowledge with any 2xx status within 10 seconds. Anything else is retried.
Example Requests
POST
/order.completed