We send a POST with JSON to your URL when something happens. Every request is signed with HMAC-SHA256.
Events
product.updated | A product or its data has changed |
passport.published | A product passport has been published in a new version |
declaration.issued | A declaration has been issued |
document.expiring | A document expires within 60 days |
review.completed | Review of a document has been completed |
How to verify the signature
The Webhook-Signature header has the form t=timestamp,v1=signature. Compute HMAC-SHA256 of "timestamp.body" with your secret and compare. Reject requests older than five minutes.
// PHP
[$t, $sig] = sscanf($_SERVER['HTTP_WEBHOOK_SIGNATURE'], 't=%d,v1=%s');
$expected = hash_hmac('sha256', $t . '.' . file_get_contents('php://input'), $secret);
if (! hash_equals($expected, $sig) || abs(time() - $t) > 300) {
http_response_code(401);
exit;
}
If your server does not reply with 2xx, we retry up to six attempts in total with increasing delays: 1, 5, 30, 120 and 360 minutes. After that the delivery goes to the failed deliveries list, from where you can send it again.