Skip to content
SALERINGOSITE v1.27.0

Webhooks

Verify the raw delivery, reject stale events, acknowledge quickly, and process each event once.

A repeat delivery must not create repeat work.Illustrative event handling, subject to the approved delivery contract.
  1. 01
    Incoming event
    Event
    customer.updated
    Payload
    Original raw bytes
  2. 02
    Verify and retain
    Signature
    Validate before processing
    Response
    Acknowledge promptly
  3. 03
    Deduplicate
    Compare
    The recorded event reference
    Already processed
    No duplicate action
Reject an invalid signature.

Keep retry limits and recovery ownership explicit. A repeated event is not a new customer request.

Contract example and implementation context
A security professional reviewing code across multiple monitors
Verify the delivery, acknowledge quickly, and process each event once.
Illustrative contract
EVENTcustomer.updated
Body
raw bytes
Signature
verified
Response
quick
Processing
once

Event catalogue, signing secret, retry schedule, retention, and support escalation are confirmed for the approved integration.

Implementation checklist

Accept an event quickly, prove it is authentic, and process it once.

Event catalogue, signing secret, retry schedule, retention, and support escalation are confirmed for the approved integration.

  1. 1 · Read raw bytesDo not parse or transform the body before signature verification.
  2. 2 · Check time and signatureReject stale timestamps and signatures that do not match the supplied secret.
  3. 3 · Acknowledge quicklyReturn the documented success response before starting long-running work.
  4. 4 · DeduplicateUse the event ID as the durable once-only processing boundary.

Request and result

Delivery headers

Saleringo-Event-Id: evt_...
Saleringo-Delivery-Timestamp: 2026-08-18T00:00:00Z
Saleringo-Delivery-Signature: v1=...

Receiver behavior

verify(rawBody, timestamp, signature)
storeOnce(eventId)
enqueue(parsedEvent)
return acceptedResponse()

Failure handling

StatusMeaningClient action
401Credential is missing, expired, or invalidStop; refresh through the approved server flow.
403Identity lacks the exact permission or scopeDo not retry; request an access review.
409State, version, idempotency, or approval conflictsRead the conflict and reconcile before another command.
422The request does not match the published schemaCorrect the named fields; do not retry unchanged.
429The integration is sending too quicklyHonor the supplied wait guidance and apply backoff.
5xxA temporary service failure may have occurredPreserve IDs; retry only when the operation permits it.

Implementation support

Do not send credentials, customer secrets, or raw payment data. Include the contract version, environment, operation, timestamp, and non-sensitive correlation ID.

Open the contact path

Check one integration contract.

Confirm authentication, permissions, timeouts, duplicate handling, and failure evidence for the approved deployment.

Open the integration guide