Entwickler
Webhooks
Tell your own systems when something happens in a conversation.
Diese Seite ist vorerst auf Englisch.
Webhooks are an action in workflows. When the workflow runs, Shopxare sends a POST request with JSON to your address.
Payload
{
"event": "conversation_closed",
"workflow": { "id": "…", "name": "Tell the CRM" },
"conversation": {
"id": "…", "status": "closed", "channel": "widget", "priority": "normal",
"assignee_id": 3, "team_id": null, "tags": ["vip"],
"last_message": "Thanks!", "url": "https://app.shopxare.com/w/…/inbox/…"
},
"contact": { "id": "…", "name": "Ada", "email": "[email protected]", "type": "user", "attributes": {} },
"sent_at": "2026-10-08T12:00:00+00:00"
}
event is the workflow's trigger: conversation_started, customer_replied, teammate_replied, conversation_closed, tag_added, unanswered_for or customer_idle_for. The header X-Shopxare-Event carries the same value.
Check the signature
Every request has a header like:
X-Shopxare-Signature: t=1760000000,v1=5f2b…
v1 is HMAC-SHA256 over "<t>.<raw body>" with the workflow's signing secret (shown in the workflow editor). Compute it yourself and compare; reject old timestamps.
[$t, $v1] = sscanf($header, 't=%d,v1=%s');
$ok = hash_equals(hash_hmac('sha256', $t.'.'.$rawBody, $secret), $v1) && abs(time() - $t) < 300;
Delivery
- The address must be public; private and local networks are refused.
- Timeout 5 seconds, no redirects.
- Up to 3 tries, waiting 30 and then 120 seconds.
- Answer with any
2xxstatus.
Noch Fragen? Kontakt