Browse the docs
API reference
Webhook endpoints
Register where events are sent, and inspect deliveries.
- POSTAdd a webhook endpoint
- GETList webhook endpoints
- GETGet a webhook endpoint
- PATCHUpdate a webhook endpoint
- DELETEDelete a webhook endpoint
- POSTRoll the signing secret
- POSTSend a test event
- GETList deliveries to an endpoint
- POSTRetry a delivery now
Add a webhook endpoint
/v1/webhook-endpointsThe response includes the signing secret, shown only now and when rolled.
Parameters
Idempotency-Keystring · headerAny unique string (a UUID is ideal). Retrying with the same key returns the first result instead of acting twice. Kept for 24 hours.
Request body
urlstringrequireddescriptionstringeventsarray of enum
Returns · WebhookEndpoint
Show 10 fields
objectstringiduuidrequiredmodeanyrequiredWhich environment's events it receives. *
live- live *test- testurlstringrequireddescriptionstringrequiredeventsarray of stringrequiredEmpty means every event.
statusenumrequired*
ACTIVE- ACTIVE *DISABLED- DISABLEDACTIVEDISABLEDdisabled_reasonstringrequiredcreated_attimestamprequiredsecretstringSigning secret. Returned only on create and roll.
Errors: 400, 403, in the standard error format.
curl -X POST https://sandbox.api.scanimart.com/v1/webhook-endpoints \
-H "Authorization: Bearer $SCANIMART_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{
"url": "https://pos.example.com/scanimart/webhooks",
"description": "Billing server",
"events": [
"order.placed"
]
}'{
"object": "webhook_endpoint",
"id": "ORDER-1A2B3C4D5E",
"mode": null,
"url": "https://pos.example.com/scanimart/webhooks",
"description": "Billing server",
"events": [
"string"
],
"status": "ACTIVE",
"disabled_reason": "string",
"created_at": "2026-10-08T10:15:00+05:30",
"secret": "string"
}List webhook endpoints
/v1/webhook-endpointsReturns · WebhookEndpointList
Show 4 fields
objectstringdataarray of objectrequiredobjectstringiduuidrequiredmodeanyrequiredWhich environment's events it receives. *
live- live *test- testurlstringrequireddescriptionstringrequiredeventsarray of stringrequiredEmpty means every event.
statusenumrequired*
ACTIVE- ACTIVE *DISABLED- DISABLEDACTIVEDISABLEDdisabled_reasonstringrequiredcreated_attimestamprequiredsecretstringSigning secret. Returned only on create and roll.
has_morebooleanrequirednext_cursorstringnullablerequiredPass as
cursorto get the next page.
Errors: 403, in the standard error format.
curl https://sandbox.api.scanimart.com/v1/webhook-endpoints \
-H "Authorization: Bearer $SCANIMART_KEY"{
"object": "list",
"data": [
{
"object": "webhook_endpoint",
"id": "ORDER-1A2B3C4D5E",
"mode": null,
"url": "https://pos.example.com/scanimart/webhooks",
"description": "Billing server",
"events": [
"string"
],
"status": "ACTIVE",
"disabled_reason": "string",
"created_at": "2026-10-08T10:15:00+05:30",
"secret": "string"
}
],
"has_more": false,
"next_cursor": null
}Get a webhook endpoint
/v1/webhook-endpoints/{endpoint_id}Looks up one of the caller's endpoints. Holds no handlers itself: the sub-resource views (roll-secret, test, deliveries) inherit only this, never the detail view's GET/PATCH/DELETE -- otherwise DELETE .../test would delete the endpoint.
Parameters
endpoint_iduuid · pathrequired
Returns · WebhookEndpoint
Show 10 fields
objectstringiduuidrequiredmodeanyrequiredWhich environment's events it receives. *
live- live *test- testurlstringrequireddescriptionstringrequiredeventsarray of stringrequiredEmpty means every event.
statusenumrequired*
ACTIVE- ACTIVE *DISABLED- DISABLEDACTIVEDISABLEDdisabled_reasonstringrequiredcreated_attimestamprequiredsecretstringSigning secret. Returned only on create and roll.
Errors: 403, in the standard error format.
curl https://sandbox.api.scanimart.com/v1/webhook-endpoints/3f1c9a2e-6b7d-4c1a-9f0e-2d8b5a7c4e10 \
-H "Authorization: Bearer $SCANIMART_KEY"{
"object": "webhook_endpoint",
"id": "ORDER-1A2B3C4D5E",
"mode": null,
"url": "https://pos.example.com/scanimart/webhooks",
"description": "Billing server",
"events": [
"string"
],
"status": "ACTIVE",
"disabled_reason": "string",
"created_at": "2026-10-08T10:15:00+05:30",
"secret": "string"
}Update a webhook endpoint
/v1/webhook-endpoints/{endpoint_id}Setting status to ACTIVE re-enables an endpoint that was switched off after repeated failures.
Parameters
endpoint_iduuid · pathrequired
Request body
urlstringdescriptionstringeventsarray of enumstatusenum*
ACTIVE- ACTIVE *DISABLED- DISABLEDACTIVEDISABLED
Returns · WebhookEndpoint
Show 10 fields
objectstringiduuidrequiredmodeanyrequiredWhich environment's events it receives. *
live- live *test- testurlstringrequireddescriptionstringrequiredeventsarray of stringrequiredEmpty means every event.
statusenumrequired*
ACTIVE- ACTIVE *DISABLED- DISABLEDACTIVEDISABLEDdisabled_reasonstringrequiredcreated_attimestamprequiredsecretstringSigning secret. Returned only on create and roll.
Errors: 403, in the standard error format.
curl -X PATCH https://sandbox.api.scanimart.com/v1/webhook-endpoints/3f1c9a2e-6b7d-4c1a-9f0e-2d8b5a7c4e10 \
-H "Authorization: Bearer $SCANIMART_KEY" \
-H "Content-Type: application/json" \
-d '{
"url": "https://pos.example.com/scanimart/webhooks",
"description": "Billing server",
"events": [
"order.placed"
],
"status": "ACTIVE"
}'{
"object": "webhook_endpoint",
"id": "ORDER-1A2B3C4D5E",
"mode": null,
"url": "https://pos.example.com/scanimart/webhooks",
"description": "Billing server",
"events": [
"string"
],
"status": "ACTIVE",
"disabled_reason": "string",
"created_at": "2026-10-08T10:15:00+05:30",
"secret": "string"
}Delete a webhook endpoint
/v1/webhook-endpoints/{endpoint_id}Looks up one of the caller's endpoints. Holds no handlers itself: the sub-resource views (roll-secret, test, deliveries) inherit only this, never the detail view's GET/PATCH/DELETE -- otherwise DELETE .../test would delete the endpoint.
Parameters
endpoint_iduuid · pathrequired
Errors: 403, in the standard error format.
curl -X DELETE https://sandbox.api.scanimart.com/v1/webhook-endpoints/3f1c9a2e-6b7d-4c1a-9f0e-2d8b5a7c4e10 \
-H "Authorization: Bearer $SCANIMART_KEY"Roll the signing secret
/v1/webhook-endpoints/{endpoint_id}/roll-secretThe old secret stops working immediately. Update your receiver before calling this.
Parameters
endpoint_iduuid · pathrequired
Returns · WebhookEndpoint
Show 10 fields
objectstringiduuidrequiredmodeanyrequiredWhich environment's events it receives. *
live- live *test- testurlstringrequireddescriptionstringrequiredeventsarray of stringrequiredEmpty means every event.
statusenumrequired*
ACTIVE- ACTIVE *DISABLED- DISABLEDACTIVEDISABLEDdisabled_reasonstringrequiredcreated_attimestamprequiredsecretstringSigning secret. Returned only on create and roll.
Errors: 403, in the standard error format.
curl -X POST https://sandbox.api.scanimart.com/v1/webhook-endpoints/3f1c9a2e-6b7d-4c1a-9f0e-2d8b5a7c4e10/roll-secret \
-H "Authorization: Bearer $SCANIMART_KEY"{
"object": "webhook_endpoint",
"id": "ORDER-1A2B3C4D5E",
"mode": null,
"url": "https://pos.example.com/scanimart/webhooks",
"description": "Billing server",
"events": [
"string"
],
"status": "ACTIVE",
"disabled_reason": "string",
"created_at": "2026-10-08T10:15:00+05:30",
"secret": "string"
}Send a test event
/v1/webhook-endpoints/{endpoint_id}/testSends one event to this endpoint now and reports how it answered. With bad_signature: true the signature is deliberately wrong -- a correct receiver answers 4xx (this is on the go-live checklist).
Parameters
endpoint_iduuid · pathrequired
Request body
typeanybad_signaturebooleanSend with a deliberately wrong signature. Your endpoint should answer 4xx.
Returns · WebhookDelivery
Show 11 fields
objectstringidintegerrequiredevent_idstringrequiredevent_typestringrequiredstatusenumrequired*
PENDING- PENDING *SUCCEEDED- SUCCEEDED *DEAD- DEADPENDINGSUCCEEDEDDEADattemptsintegerrequirednext_attempt_attimestampnullablerequiredlast_status_codeintegernullablerequiredlast_errorstringrequiredcreated_attimestamprequiredsucceeded_attimestampnullablerequired
Errors: 403, in the standard error format.
curl -X POST https://sandbox.api.scanimart.com/v1/webhook-endpoints/3f1c9a2e-6b7d-4c1a-9f0e-2d8b5a7c4e10/test \
-H "Authorization: Bearer $SCANIMART_KEY" \
-H "Content-Type: application/json" \
-d '{
"type": "ping",
"bad_signature": false
}'{
"object": "webhook_delivery",
"id": 1,
"event_id": "evt_8f14e45fceea167a5a36dedd4bea2543",
"event_type": "string",
"status": "PENDING",
"attempts": 1,
"next_attempt_at": "2026-10-08T10:15:00+05:30",
"last_status_code": 1,
"last_error": "string",
"created_at": "2026-10-08T10:15:00+05:30",
"succeeded_at": "2026-10-08T10:15:00+05:30"
}List deliveries to an endpoint
/v1/webhook-endpoints/{endpoint_id}/deliveriesLooks up one of the caller's endpoints. Holds no handlers itself: the sub-resource views (roll-secret, test, deliveries) inherit only this, never the detail view's GET/PATCH/DELETE -- otherwise DELETE .../test would delete the endpoint.
Parameters
endpoint_iduuid · pathrequiredcursorstring · queryOpaque cursor from a previous page's
next_cursor.limitinteger · queryPage size, 1–100. Default 50.
statusenum · queryDEADPENDINGSUCCEEDED
Returns · WebhookDeliveryList
Show 4 fields
objectstringdataarray of objectrequiredobjectstringidintegerrequiredevent_idstringrequiredevent_typestringrequiredstatusenumrequired*
PENDING- PENDING *SUCCEEDED- SUCCEEDED *DEAD- DEADPENDINGSUCCEEDEDDEADattemptsintegerrequirednext_attempt_attimestampnullablerequiredlast_status_codeintegernullablerequiredlast_errorstringrequiredcreated_attimestamprequiredsucceeded_attimestampnullablerequired
has_morebooleanrequirednext_cursorstringnullablerequiredPass as
cursorto get the next page.
Errors: 403, in the standard error format.
curl https://sandbox.api.scanimart.com/v1/webhook-endpoints/3f1c9a2e-6b7d-4c1a-9f0e-2d8b5a7c4e10/deliveries \
-H "Authorization: Bearer $SCANIMART_KEY"{
"object": "list",
"data": [
{
"object": "webhook_delivery",
"id": 1,
"event_id": "evt_8f14e45fceea167a5a36dedd4bea2543",
"event_type": "string",
"status": "PENDING",
"attempts": 1,
"next_attempt_at": "2026-10-08T10:15:00+05:30",
"last_status_code": 1,
"last_error": "string",
"created_at": "2026-10-08T10:15:00+05:30",
"succeeded_at": "2026-10-08T10:15:00+05:30"
}
],
"has_more": false,
"next_cursor": null
}Retry a delivery now
/v1/webhook-deliveries/{delivery_id}/retryRe-sends a failed or given-up delivery straight away.
Parameters
delivery_idinteger · pathrequired
Returns · WebhookDelivery
Show 11 fields
objectstringidintegerrequiredevent_idstringrequiredevent_typestringrequiredstatusenumrequired*
PENDING- PENDING *SUCCEEDED- SUCCEEDED *DEAD- DEADPENDINGSUCCEEDEDDEADattemptsintegerrequirednext_attempt_attimestampnullablerequiredlast_status_codeintegernullablerequiredlast_errorstringrequiredcreated_attimestamprequiredsucceeded_attimestampnullablerequired
Errors: 403, in the standard error format.
curl -X POST https://sandbox.api.scanimart.com/v1/webhook-deliveries/88/retry \
-H "Authorization: Bearer $SCANIMART_KEY"{
"object": "webhook_delivery",
"id": 1,
"event_id": "evt_8f14e45fceea167a5a36dedd4bea2543",
"event_type": "string",
"status": "PENDING",
"attempts": 1,
"next_attempt_at": "2026-10-08T10:15:00+05:30",
"last_status_code": 1,
"last_error": "string",
"created_at": "2026-10-08T10:15:00+05:30",
"succeeded_at": "2026-10-08T10:15:00+05:30"
}