Skip to main content
B2B Glossary / Webhook

What Is a Webhook?

Last updated

In this article Talk to our experts
Definition
Webhook
A webhook is an HTTP request one system sends to another when an event happens, such as an order being created. The receiving system registers a URL for the events it wants, and the sender posts the event data there, instead of the receiver repeatedly polling an API to ask whether anything changed.

Also called: web hook

How it works

The W3C's WebSub standard describes its mechanism for communication between publishers and subscribers as based on HTTP web hooks. A subscriber is identified by its callback URL, the address where it wants to receive content, and the hub delivers each update as an HTTP POST request to that URL. The subscriber acknowledges with an HTTP 2xx status code.

Shopify's own webhooks follow the same pattern. A subscription declares which topic to watch and where to send deliveries. A topic identifies the resource and the action, such as products/create, which fires when a new product is created. Shopify describes webhooks as a performant alternative to continuously polling for changes to a shop's data.

How a webhook delivery works on Shopify

1
Subscribe
Declare the topic

The app subscribes to a topic such as orders/create and names the endpoint where deliveries go.

2
Event
Order created

An order is created in the shop, which triggers a webhook on the orders/create topic.

3
Deliver
HTTP POST

Shopify sends the webhook, with headers and an order payload, to the subscription endpoint.

4
Verify
Check the signature

The receiver verifies the HMAC signature to confirm the delivery came from Shopify.

5
Acknowledge
200 OK

The receiver answers with a 200 OK. Shopify allows five seconds for the whole request.

What a delivery contains

For HTTPS destinations, Shopify sends an HTTP POST with a JSON payload in the request body and delivery metadata in HTTP headers. By default, the payload contains the full REST resource for the topic. The headers include:

  • X-Shopify-Topic: the topic name, for example products/update.
  • X-Shopify-Hmac-Sha256: a base64-encoded HMAC signature for verifying the delivery came from Shopify.
  • X-Shopify-Shop-Domain: the myshopify.com domain of the store that triggered the event.
  • X-Shopify-Webhook-Id: a unique key per delivery, used to identify and deduplicate individual deliveries.
  • X-Shopify-Triggered-At: the timestamp of when Shopify triggered the delivery.
  • X-Shopify-Event-Id: a unique ID shared across all deliveries produced by the same merchant action.

Common problems

Shopify's documentation flags these issues for apps that receive webhooks:

  • Out of order delivery. Shopify doesn't guarantee ordering within a topic, or across topics for the same resource. A products/update webhook can arrive before products/create.
  • Duplicates. The same webhook can arrive more than once, for example after a network timeout or a retry.
  • Missed events. Delivery isn't always guaranteed, so Shopify recommends reconciliation jobs that periodically fetch data from Shopify.
  • Failed or slow responses. Any response outside the 200 range counts as an error, and Shopify allows five seconds for the entire request. If it gets no response or an error, Shopify retries 8 times over the next 4 hours, and after 8 consecutive failures it deletes a subscription that was configured using the Admin API.

Example

A distributor syncs Shopify orders into its ERP. Polling the orders API every 5 minutes means 24 x 60 / 5 = 288 requests a day, whether or not anything changed. With one orders/create subscription, a day with 40 new orders means 40 deliveries, one per order.

Order 1042 arrives twice after a network timeout. Both deliveries carry the same X-Shopify-Webhook-Id, so the integration processes the first, finds the ID already saved on the second, skips it and still returns a success response. A nightly reconciliation job then catches anything a webhook missed.

On Shopify

Apps declare subscriptions in shopify.app.toml or through the GraphQL Admin API. Deliveries can go to an HTTPS URL, a Google Pub/Sub URI or an Amazon EventBridge ARN, and HMAC verification applies to HTTPS deliveries only. Shopify lists integrating order data with accounting software among the things you can build with webhooks. Its webhook reference lists company topics such as companies/create, which occurs whenever a company is created, next to order topics such as orders/create and orders/edited.

How Uncap helps

Uncap Connect is the real-time data layer between Shopify, your ERP, and the warehouse floor: inventory, orders, customers, and pricing move the moment they change, not in an overnight batch. A live console shows every sync, flags conflicts, and replays anything that fails.

Sources

09 Common questions

Frequently asked questions

What is the difference between API and webhook?

With an API, your system asks for data whenever it wants it. With a webhook, the source system sends the data when the event happens, which Shopify describes as a performant alternative to continuously polling for changes.

Can you give me an example of a webhook?

When an order is created in a Shopify store, a webhook on the orders/create topic sends the order data, with headers and an order payload, to the endpoint the app subscribed with.

How do I test a webhook?

On Shopify, update a development store to trigger one, for example create a product to trigger products/create. For an app created in the Dev Dashboard or with Shopify CLI, the delivery logs then show the response code your app returned.

Talk to Our Experts →