Webhooks, kotorye ne vrut.

Podpisannye, s zashchitoi ot replay i povtorami do vashego 2xx.

Podpishites na invoice / order / refund events. Proveryaite HMAC-SHA256 na svoem endpoint. Kazhdaya dostavka podpisana HMAC-SHA256, imeet timestamp i povtory s exponential back-off do otveta 2xx.

Katalog

Devyat events. Podpishites na vse ili na odin.

order.paid A buyer's payment was accepted.
order.failed Payment or checkout processing failed.
order.refunded The order was fully refunded.
delivery.completed A line item was delivered successfully.
delivery.failed A line-item delivery failed.
Headers

Chto prihodit na vash endpoint

POST /your-endpoint
# Standard headers Sellix sets on every delivery
X-Sellix-Event-Id:   7a2327ba-8655-45b4-a768-13e2112b2556
X-Sellix-Event:      order.paid
X-Sellix-Signature:  8f7a9a2b…
Content-Type:        application/json

# The exact raw body covered by X-Sellix-Signature
{
  "id": "7a2327ba-8655-45b4-a768-13e2112b2556",
  "object": "event",
  "event": "order.paid",
  "created_at": "2026-05-26T07:14:22Z",
  "data": { "order": { "uuid": "…", "total_cents": 4900, … } }
}
Interactive

HMAC-SHA256 verifier

Vstavte payload i secret. My schitaem signature v browser cherez Web Crypto API - tot zhe algoritm, chto v SDK.

Vstavte signature vyshe, chtoby proverit.
Implementation

Ta zhe proverka na vashem yazyke


            

Retry policy

  • Up to 6 attempts per delivery
  • Back-off: 10s → 30s → 2m → 10m → 1h
  • Any 2xx ends the chain; every non-2xx retries
  • After 20 cumulative failed attempts, the endpoint is disabled.

Replay & dedupe

  • Verify X-Sellix-Signature against the exact raw request body.
  • Dedupe by X-Sellix-Event-Id. Retries keep the same id and body.
  • A replayed event should also return 200 - it's a feature, not a duplicate.