Webhooks 不会说谎。

签名、重放保护、重试,直到 2xx。

订阅发票/订单/退款事件。验证端点中的 HMAC-SHA256。 每次交付均经过 HMAC-SHA256 签名、加盖时间戳,并以指数回退方式重试,直到您的端点返回 2xx。

目录

九个事件。订阅全部或一个。

order.paid A buyer's payment was accepted.
order.failed Payment or checkout processing failed.
order.refunded The order was fully refunded.
delivery.completed A line item was delivered successfully.
delivery.failed A line-item delivery failed.
标头

什么落在您的端点上

POST /your-endpoint
# Standard headers Sellix sets on every delivery
X-Sellix-Event-Id:   7a2327ba-8655-45b4-a768-13e2112b2556
X-Sellix-Event:      order.paid
X-Sellix-Signature:  8f7a9a2b…
Content-Type:        application/json

# The exact raw body covered by X-Sellix-Signature
{
  "id": "7a2327ba-8655-45b4-a768-13e2112b2556",
  "object": "event",
  "event": "order.paid",
  "created_at": "2026-05-26T07:14:22Z",
  "data": { "order": { "uuid": "…", "total_cents": 4900, … } }
}
交互的

HMAC-SHA256 验证者

粘贴有效负载+秘密。我们使用 Web Crypto API 在您的浏览器中实时计算签名 - 我们的 SDK 在您的服务器上使用相同的算法。

在上面粘贴签名以进行检查。
执行

同样的支票,用您的语言


            

重试政策

  • Up to 6 attempts per delivery
  • Back-off: 10s → 30s → 2m → 10m → 1h
  • Any 2xx ends the chain; every non-2xx retries
  • After 20 cumulative failed attempts, the endpoint is disabled.

重播和重复数据删除

  • Verify X-Sellix-Signature against the exact raw request body.
  • Dedupe by X-Sellix-Event-Id. Retries keep the same id and body.
  • A replayed event should also return 200 - it's a feature, not a duplicate.