Webhooks & events

Every commerce event, signed, retried, and accounted for.

Ninety-nine signed event types with automatic retries, replay, send-test, delivery logs, secret rotation, and alerts when an endpoint starts failing.

The record of everything that happens

Throttle emits an event for each step of the commerce lifecycle — 99 types across carts, orders, payments, subscriptions, quotes, invoices, customers, fulfillments, returns, and discounts — and delivers them to your endpoints. Your ERP, CRM, warehouse, and email platform hear about an order the moment it exists, not on the next nightly sync.

The catalog is published as an API and as TypeScript types (@usethrottle/webhook-types), so your handler knows every payload’s shape at compile time.

Signed, so you know it’s us

Every delivery carries an HMAC-SHA256 signature with a timestamp, plus the event id and type in headers. Rotate a signing secret without downtime: old and new secrets both sign during a grace window of up to seven days.

Delivered, or you’ll know why

  • Retries on a fixed schedule — 5 minutes, 15 minutes, 1 hour, 6 hours, 24 hours — before an event is dead-lettered.
  • No pointless retries. A delivery that can never succeed — an invalid or non-HTTPS URL, an unresolvable host, a private address — is dead-lettered at once.
  • Delivery log for every attempt, with replay for any delivery and send-test for any endpoint.
  • Coverage check that lists events your application emitted that no endpoint is subscribed to.

Alerts before your customers notice

  • An immediate email and in-app alert when an endpoint starts rejecting deliveries as unauthorized.
  • An hourly digest when deliveries fail in bulk.
  • An endpoint that has failed every delivery for a week is switched off automatically, and you’re told.

Test never leaks into live

Endpoints belong to an environment: a test event is only ever delivered to a test endpoint, and a test key can’t disable or replay a production endpoint.

Good to know

  • Subscribing to an event requires the matching read scope, checked when the endpoint is registered.
  • The retry schedule is fixed.
  • The CLI manages endpoints, deliveries, replay, and send-test; it doesn’t tunnel events to localhost.