Webhooks
Push-based event delivery for partner systems that don't want to poll.
WHost dispatches a signed POST to each registered endpoint when one of
the supported events fires (account.created, account.suspended,
license.state_changed, webhook.failed, …).
Brief flow:
- Operator registers an endpoint via
POST /api/v1/webhooks/endpoints. - WHost stores the endpoint with a per-endpoint signing secret.
- When an audit-logged event occurs, the dispatcher posts to the URL
with headers
X-WHost-Event,X-WHost-Delivery-Id,X-WHost-Signature,X-WHost-Timestampand a JSON body. - The receiver verifies the signature (use the PHP SDK's
WHost\Webhook\WebhookVerifieror the canonical formula:HMAC-SHA256(secret, "{timestamp}.{body}")). - Non-2xx replies trigger exponential-backoff retries; after the
final attempt the delivery lands in the dead-letter queue and
surfaces in
/admin/webhooks → Deliveries → Failed.
Full event catalog, payload shapes, retry policy and signature
verification recipes — and the subscriber-side secret rotation
playbook (no rolling window; two-deploy coordination required) — are
in docs/developer/webhooks.md.
Still Need Help?
Our support team is here around the clock for anything you can't find above.