AApt Commerce
Sign inGet started
Show for

Webhooks

Receive real-time HTTP POST notifications when events occur in your account.

Event Types

payment.completed

A payment has been successfully processed

payment.failed

A payment attempt has failed

payment.refunded

A payment has been fully or partially refunded

customer.created

A new customer record was created

customer.updated

Customer information was updated

invoice.created

A new invoice was created

invoice.sent

An invoice was sent to the customer

invoice.paid

An invoice has been paid

invoice.overdue

An invoice is past its due date

subscription.created

A new subscription was started

subscription.renewed

A subscription billing cycle renewed

subscription.cancelled

A subscription was cancelled

subscription.past_due

A subscription payment failed

payout.completed

A payout has funded to your bank (distinct from payment SETTLED)

dispute.created

A chargeback or dispute was opened

dispute.resolved

A dispute was resolved

tls.cipher_policy.changed

APT cipher suite policy changed — review your client posture

tls.protocol.deprecated

A TLS protocol version has entered its 12-month sunset window

certificate.rotated

Edge certificate or issuing CA rotated

mle.key.rotated

Your message-level encryption public key rotated

mle.policy.changed

An endpoint will require MLE — at least 12 months ahead of enforcement

Payload Structure

{
  "id": "evt_1a2b3c4d",
  "type": "payment.completed",
  "created_at": "2026-03-14T12:00:00Z",
  "data": {
    "object": {
      "id": "txn_abc123",
      "amount": 9900,
      "currency": "usd",
      "status": "completed"
    }
  }
}

Signature Verification

Each webhook includes an X-AptCommerce-Signature header. Verify it to ensure the request is authentic.

const crypto = require('crypto');

function verifyWebhook(payload, signature, secret) {
  const expected = crypto
    .createHmac('sha256', secret)
    .update(payload)
    .digest('hex');
  return crypto.timingSafeEqual(
    Buffer.from(signature),
    Buffer.from(expected)
  );
}

Retry Policy

Failed deliveries are retried up to 5 times with exponential backoff: 1 min, 5 min, 30 min, 2 hours, 24 hours. After all retries fail, the endpoint is marked as failing.

Best Practices

  • Always verify webhook signatures before processing.
  • Return a 200 response quickly. Process the event asynchronously.
  • Handle duplicate events idempotently using the event id.
  • Use the webhook settings page to test deliveries.