Security
Keep your endpoints and your customers' data safe.
Checklist
- Verify every signature and reject stale timestamps — see Verify signatures.
- Keep the signing secret secret. Store it like a password (environment variable or secret manager), never in client-side code or a repository.
- Rotate the secret if it may have been exposed. The old one keeps working for 24 hours.
- Use HTTPS only. Zaher refuses
http://URLs. - Restrict who can manage webhooks. In Settings → Employees, only roles with the Webhooks → Manage permission can add endpoints or reveal secrets. Every change is recorded in the store's audit log.
What Zaher blocks
To protect its own infrastructure, Zaher only delivers to public addresses.
URLs that resolve to localhost, private networks (10.x, 192.168.x,
172.16–31.x), link-local or cloud metadata addresses are refused, and
redirects are never followed.
Customer data
Payloads contain personal data about your customers — names, emails, phone numbers and addresses — so you can fulfil orders and keep your systems in sync.
You are responsible for your endpoints
Data sent to an endpoint you configure is under your control and your responsibility. Only add endpoints you trust, protect the systems that receive the data, and handle it in line with the privacy laws that apply to your store.
Zaher keeps webhook events and delivery logs for 30 days, then deletes them permanently.