Skip to content
GuidesAPI v1admin-sdk 1.1.52Search docs⌘K
Webhooks · Webhooks
Guides / Webhooks

Webhooks

Inkress posts JSON to your server when something happens to a merchant you work with: an order is paid, a subscription renews.

Add an endpoint

Add an HTTPS URL under Webhooks in the portal, or with POST /api/v1/webhook_urls and the event it should get. Use orders for every order event, subscriptions for every subscription event, or all. An endpoint gets one event or group; add more endpoints for more.

Endpoints an app registers get deliveries for every merchant who installed it, signed with the app's own webhook secret (whsec_…).

What we send

A POST with a JSON body and these headers:

HeaderWhat it holds
X-Inkress-Webhook-SignatureBase64 HMAC-SHA256 of the raw body, keyed with the signing secret.
X-Inkress-Webhook-EventThe event, e.g. orders.paid.
X-Inkress-Webhook-IDThe same for every retry of one delivery. Use it to skip repeats.
X-Inkress-Order-IDOn order events: the order's ID.
X-Inkress-Subscription-IDOn subscription events: the subscription's ID.
Content-Typeapplication/json

Common events

EventWhen
orders.paidThe payment completed. Fulfil the order.
orders.shippedThe merchant marked the order shipped.
subscriptions.payment_successA renewal was charged.
subscriptions.payment_failedA renewal failed. The customer can update their card from a card update link.
subscriptions.trial_endingA trial ends soon.

The full list is on Event types.

Answer quickly, work later

Reply with any 2xx as soon as you've checked the signature, then do the slow work in the background. Any other answer, or no answer, counts as a failure, and Inkress tries the delivery again, up to five attempts in all.

The same event can arrive twice. Use X-Inkress-Webhook-ID to skip ones you've handled.

Rolling an app's webhook secret replaces it straight away. Have your server accept both the old and the new secret while you deploy.
Was this page helpful?Updated Oct 8, 2026