Entwickler

Webhooks

Tell your own systems when something happens in a conversation.

Webhooks are an action in workflows. When the workflow runs, Shopxare sends a POST request with JSON to your address.

Payload

{
  "event": "conversation_closed",
  "workflow": { "id": "…", "name": "Tell the CRM" },
  "conversation": {
    "id": "…", "status": "closed", "channel": "widget", "priority": "normal",
    "assignee_id": 3, "team_id": null, "tags": ["vip"],
    "last_message": "Thanks!", "url": "https://app.shopxare.com/w/…/inbox/…"
  },
  "contact": { "id": "…", "name": "Ada", "email": "[email protected]", "type": "user", "attributes": {} },
  "sent_at": "2026-10-08T12:00:00+00:00"
}

event is the workflow's trigger: conversation_started, customer_replied, teammate_replied, conversation_closed, tag_added, unanswered_for or customer_idle_for. The header X-Shopxare-Event carries the same value.

Check the signature

Every request has a header like:

X-Shopxare-Signature: t=1760000000,v1=5f2b…

v1 is HMAC-SHA256 over "<t>.<raw body>" with the workflow's signing secret (shown in the workflow editor). Compute it yourself and compare; reject old timestamps.

[$t, $v1] = sscanf($header, 't=%d,v1=%s');
$ok = hash_equals(hash_hmac('sha256', $t.'.'.$rawBody, $secret), $v1) && abs(time() - $t) < 300;

Delivery

  • The address must be public; private and local networks are refused.
  • Timeout 5 seconds, no redirects.
  • Up to 3 tries, waiting 30 and then 120 seconds.
  • Answer with any 2xx status.

Noch Fragen? Kontakt