Webhooks: subscribing to events
On this page
Webhooks push events to your endpoint as they happen, so your systems learn about a sale the moment it is rung instead of finding it on the next poll.
Creating a subscription
Under Settings โ Webhooks, add your HTTPS endpoint and tick the events you want. A signing secret is generated โ it is shown in full only at creation and masked afterwards, so store it immediately.
Available events
sale.created,sale.refundedcustomer.created,customer.updatedorder.created,order.status_changedappointment.created,appointment.cancelledinventory.adjusted
Verifying a delivery
Every request carries the event name in X-Webhook-Event and an HMAC-SHA256 signature of the payload in X-Webhook-Signature, formatted as sha256=<hex>. Recompute the HMAC over the raw request body with your secret and compare using a constant-time comparison.
Reject anything that fails verification. An endpoint that trusts an unsigned payload will happily process a forged one.
Responding
Return a 2xx as soon as you have safely stored the event, and do the real work afterwards โ a slow endpoint causes retries and eventually failures. Make your handler idempotent, since a retry can deliver the same event twice.
Failures and auto-disable
Consecutive failures are counted, and a subscription that fails ten times in a row is disabled automatically so a dead endpoint does not accumulate deliveries forever. Fix the endpoint, then re-enable it.
Testing and debugging
Use the Test button to send a sample event, and check the delivery log for each attempt with its response code and body โ the fastest way to find a wrong URL, an expired certificate, or a signature check that is comparing the wrong thing.
Note: your business can rename menu items (Settings โ POS Configuration โ Menu Labels), so the names in your menu may differ from those shown here.