In short
Webhooks let your systems react to Inno Message events in real time, such as a new incoming message. Register an HTTPS endpoint with POST /v1/webhooks, verify each request's signature using your webhook secret, and return a 2xx status quickly. Failed deliveries are retried, so your handler should be idempotent.
Example event
{
"event": "message.received",
"channel": "whatsapp",
"from": "+601234567890",
"body": "Where is my order?"
}
Verify the signature
Every webhook request is signed with your endpoint's secret, shown when you register it. Compute an HMAC-SHA256 of the raw request body with that secret and compare it to the signature header in constant time. Reject the request if they do not match.
$raw = file_get_contents('php://input');
$expected = hash_hmac('sha256', $raw, $webhookSecret);
if (!hash_equals($expected, $receivedSignature)) {
http_response_code(401);
exit;
}
Respond fast, process later
- Return a 2xx status within a few seconds, then do slow work in a background job.
- Deliveries can be retried, so store event ids and ignore duplicates.
- Only accept HTTPS endpoints you control.
Was something unclear or out of date? Tell support and we will fix the guide.

