Inkress posts JSON to your server when something happens to a merchant you work with: an order is paid, a subscription renews.
Add an endpoint
Add an HTTPS URL under Webhooks in the portal, or with POST /api/v1/webhook_urls and the event it should get. Use orders for every order event, subscriptions for every subscription event, or all. An endpoint gets one event or group; add more endpoints for more.
Endpoints an app registers get deliveries for every merchant who installed it, signed with the app's own webhook secret (whsec_…).
What we send
A POST with a JSON body and these headers:
Header
What it holds
X-Inkress-Webhook-Signature
Base64 HMAC-SHA256 of the raw body, keyed with the signing secret.
X-Inkress-Webhook-Event
The event, e.g. orders.paid.
X-Inkress-Webhook-ID
The same for every retry of one delivery. Use it to skip repeats.
X-Inkress-Order-ID
On order events: the order's ID.
X-Inkress-Subscription-ID
On subscription events: the subscription's ID.
Content-Type
application/json
Common events
Event
When
orders.paid
The payment completed. Fulfil the order.
orders.shipped
The merchant marked the order shipped.
subscriptions.payment_success
A renewal was charged.
subscriptions.payment_failed
A renewal failed. The customer can update their card from a card update link.
Reply with any 2xx as soon as you've checked the signature, then do the slow work in the background. Any other answer, or no answer, counts as a failure, and Inkress tries the delivery again, up to five attempts in all.
The same event can arrive twice. Use X-Inkress-Webhook-ID to skip ones you've handled.
Rolling an app's webhook secret replaces it straight away. Have your server accept both the old and the new secret while you deploy.