Skip to main content
Each webhook sends a JSON body with a common envelope and an event-specific payload field. The specific contract depends on eventName, majorVersion, and minorVersion.

Fields to expect

Not all events include a full copy of the entity. Design your consumer to call the API when it needs the current state.

Illustrative example

Good practices

Keep separate validators if you consume more than one major version of the same event. Do not assume that two versions have the same fields.
Display names can change. Use id or reference to reconcile data between systems.
Keep the received JSON for as long as you need it for auditing. It helps diagnose failures in an external system.
Treat the data received as sensitive information. It can contain operational references, customers, suppliers, or production quantities.

Deduplication

Use eventId to prevent processing the same business event twice. Use attemptId only to audit a specific delivery. A retry keeps the same eventId but generates a new attemptId.
If you receive the same eventId with a different attemptNumber, return 2xx after confirming that you already processed it.