Webhooks isso não mente.

Assinado, protegido contra reprodução, tentado novamente até 2xx.

Assine eventos de fatura/pedido/reembolso. Verifique HMAC-SHA256 em seu endpoint. Cada entrega é HMAC-SHA256 assinada, com carimbo de data e hora e repetida com espera exponencial até que seu endpoint retorne 2xx.

Catálogo

Nove eventos. Assine todos ou um.

order.paid A buyer's payment was accepted.
order.failed Payment or checkout processing failed.
order.refunded The order was fully refunded.
delivery.completed A line item was delivered successfully.
delivery.failed A line-item delivery failed.
Cabeçalhos

O que chega ao seu endpoint

POST /your-endpoint
# Standard headers Sellix sets on every delivery
X-Sellix-Event-Id:   7a2327ba-8655-45b4-a768-13e2112b2556
X-Sellix-Event:      order.paid
X-Sellix-Signature:  8f7a9a2b…
Content-Type:        application/json

# The exact raw body covered by X-Sellix-Signature
{
  "id": "7a2327ba-8655-45b4-a768-13e2112b2556",
  "object": "event",
  "event": "order.paid",
  "created_at": "2026-05-26T07:14:22Z",
  "data": { "order": { "uuid": "…", "total_cents": 4900, … } }
}
Interativo

HMAC-SHA256 verificador

Cole uma carga útil + segredo. Calculamos a assinatura ao vivo no seu navegador usando o Web Crypto API - o mesmo algoritmo que nosso SDK usa no seu servidor.

Cole uma assinatura acima para verificar.
Implementação

Mesmo cheque, no seu idioma


            

Política de repetição

  • Up to 6 attempts per delivery
  • Back-off: 10s → 30s → 2m → 10m → 1h
  • Any 2xx ends the chain; every non-2xx retries
  • After 20 cumulative failed attempts, the endpoint is disabled.

Repetir e desduplicar

  • Verify X-Sellix-Signature against the exact raw request body.
  • Dedupe by X-Sellix-Event-Id. Retries keep the same id and body.
  • A replayed event should also return 200 - it's a feature, not a duplicate.