Help

Getting started

We send a POST with JSON to your URL when something happens. Every request is signed with HMAC-SHA256.

Events

product.updatedA product or its data has changed
passport.publishedA product passport has been published in a new version
declaration.issuedA declaration has been issued
document.expiringA document expires within 60 days
review.completedReview of a document has been completed

How to verify the signature

The Webhook-Signature header has the form t=timestamp,v1=signature. Compute HMAC-SHA256 of "timestamp.body" with your secret and compare. Reject requests older than five minutes.

// PHP
[$t, $sig] = sscanf($_SERVER['HTTP_WEBHOOK_SIGNATURE'], 't=%d,v1=%s');
$expected = hash_hmac('sha256', $t . '.' . file_get_contents('php://input'), $secret);
if (! hash_equals($expected, $sig) || abs(time() - $t) > 300) {
    http_response_code(401);
    exit;
}

If your server does not reply with 2xx, we retry up to six attempts in total with increasing delays: 1, 5, 30, 120 and 360 minutes. After that the delivery goes to the failed deliveries list, from where you can send it again.