Webhooks

Updated Oct 3, 2026 Markdown

Push-based event delivery for partner systems that don't want to poll. WHost dispatches a signed POST to each registered endpoint when one of the supported events fires (account.created, account.suspended, license.state_changed, webhook.failed, …).

Brief flow:

  1. Operator registers an endpoint via POST /api/v1/webhooks/endpoints.
  2. WHost stores the endpoint with a per-endpoint signing secret.
  3. When an audit-logged event occurs, the dispatcher posts to the URL with headers X-WHost-Event, X-WHost-Delivery-Id, X-WHost-Signature, X-WHost-Timestamp and a JSON body.
  4. The receiver verifies the signature (use the PHP SDK's WHost\Webhook\WebhookVerifier or the canonical formula: HMAC-SHA256(secret, "{timestamp}.{body}")).
  5. Non-2xx replies trigger exponential-backoff retries; after the final attempt the delivery lands in the dead-letter queue and surfaces in /admin/webhooks → Deliveries → Failed.

Full event catalog, payload shapes, retry policy and signature verification recipes — and the subscriber-side secret rotation playbook (no rolling window; two-deploy coordination required) — are in docs/developer/webhooks.md.

Still Need Help?

Our support team is here around the clock for anything you can't find above.