Events
Every event and what its payload holds.
Verify signatures
Check each request came from Saasybill.
Delivery and retries
What happens when your server is down.
Set up an endpoint
Endpoints are managed in the app. The API doesn’t manage them yet. Only an owner or admin can add one.1
Open Webhooks
Go to Organisation Settings, then Developer Settings, then Webhooks.
2
Add the endpoint
Click Add Endpoint and fill in the fields.
3
Copy the signing secret
Click Add Endpoint. The Your Signing Secret dialog shows a secret beginning
whsec_. Copy it now and store it as an environment variable. It can’t be shown again.4
Send a test event
Open the endpoint’s menu and click Send Test Event. Confirm your server receives it and passes signature verification.
Endpoint rules
The address is checked when you save the URL and again on every delivery.
Manage an endpoint
Each endpoint has a menu.What a webhook looks like
Saasybill sends aPOST with a JSON body.
The event object
Events are thin on purpose. They carry the fields that changed and no more. To get the full object, fetch it with its
id, for example GET /v1/invoices/{id}.Respond quickly
Reply with any2xx status within 10 seconds. Acknowledge the event first and do the slow work afterwards, on a queue or a background job. Anything else is a failure and is retried.
Things to know
Events can arrive up to a minute late
Events can arrive up to a minute late
Saasybill finds changes about once a minute by comparing each object with how it looked last time. An event arrives up to a minute after the change.
Changes inside one minute are combined
Changes inside one minute are combined
An invoice that is approved and paid within the same minute arrives as one
invoice.paid event, and previous_attributes.status is draft. You won’t see an approved step. Write your handler to depend on the current state, not on seeing every step.Events can arrive more than once
Events can arrive more than once
Delivery is at-least-once. Store each
Saasybill-Event-Id you have processed and skip repeats.Events can arrive out of order
Events can arrive out of order
Order is not guaranteed, and a retry can arrive after a newer event. If order matters, fetch the object from the API and act on its current state.
A new endpoint doesn't announce what already exists
A new endpoint doesn't announce what already exists
When an organisation gets its first endpoint, Saasybill records the current state silently. You’ll hear about changes from then on, not about every existing invoice.
Only customers are announced, not every contact
Only customers are announced, not every contact
A Xero contact that hasn’t been imported as a customer produces no events until it is imported.