Prompt
receive shopify webhook event
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
To receive a Shopify webhook event, you need to:
-
Create a webhook subscription in Shopify
- Either from your app/admin, or via API.
- Set the callback URL to your server endpoint, e.g.:
https://yourdomain.com/webhooks/orders/create
-
Expose a public HTTPS endpoint
- Shopify only sends webhooks to a publicly reachable HTTPS URL.
- Your endpoint must accept the HTTP method Shopify uses for that topic, usually POST.
-
Read the request body exactly as sent
- Shopify signs the raw payload, so you need the raw request body for verification.
-
Verify the webhook
- Check the
X-Shopify-Hmac-Sha256header using your app secret. - Also validate
X-Shopify-Shop-Domain,X-Shopify-Topic, andX-Shopify-Webhook-Idas needed.
- Check the
-
Return a quick
200 OK- Shopify expects a fast response.
- Do async processing after acknowledging the request.
Example: Node.js / Express
import express from "express";
import crypto from "crypto";
const app = express();
// Use raw body for webhook route
app.post("/webhooks/orders-create", express.raw({ type: "application/json" }), (req, res) => {
const hmac = req.get("X-Shopify-Hmac-Sha256");
const secret = process.env.SHOPIFY_WEBHOOK_SECRET;
const generatedHash = crypto
.createHmac("sha256", secret)
.update(req.body, "utf8")
.digest("base64");
if (generatedHash !== hmac) {
return res.status(401).send("Unauthorized");
}
const data = JSON.parse(req.body.toString("utf8"));
console.log("Received webhook:", data);
res.sendStatus(200);
});
app.listen(3000, () => console.log("Listening on port 3000"));
Common webhook headers from Shopify
X-Shopify-TopicX-Shopify-Shop-DomainX-Shopify-Hmac-Sha256X-Shopify-Webhook-IdX-Shopify-API-Version
If you want to register the webhook via API
You can do it using the Admin API GraphQL or REST, depending on your app setup.
If you want, I can give you:
- a Python / FastAPI example,
- a Next.js example,
- or the code to register Shopify webhooks automatically.
Brands