In short

Webhooks let your systems react to Inno Message events in real time, such as a new incoming message. Register an HTTPS endpoint with POST /v1/webhooks, verify each request's signature using your webhook secret, and return a 2xx status quickly. Failed deliveries are retried, so your handler should be idempotent.

Example event

webhook.json
{
  "event": "message.received",
  "channel": "whatsapp",
  "from": "+601234567890",
  "body": "Where is my order?"
}

Verify the signature

Every webhook request is signed with your endpoint's secret, shown when you register it. Compute an HMAC-SHA256 of the raw request body with that secret and compare it to the signature header in constant time. Reject the request if they do not match.

verify.php
$raw = file_get_contents('php://input');
$expected = hash_hmac('sha256', $raw, $webhookSecret);
if (!hash_equals($expected, $receivedSignature)) {
    http_response_code(401);
    exit;
}

Respond fast, process later

  • Return a 2xx status within a few seconds, then do slow work in a background job.
  • Deliveries can be retried, so store event ids and ignore duplicates.
  • Only accept HTTPS endpoints you control.

Was something unclear or out of date? Tell support and we will fix the guide.