Webhooks

On the Pro plan, DockGuard can POST events to an https endpoint you choose (DockGuard → Integrations). Deliveries are signed so you can verify they came from DockGuard.

Events

Saving the endpoint sends a test incident.opened with data.test = true.

Request

POST your-endpoint
Content-Type: application/json
X-DockGuard-Event: incident.opened
X-DockGuard-Delivery: clx…          (unique, use it to deduplicate)
X-DockGuard-Signature: sha256=<hex>

{"id":"clx…","event":"incident.opened","shop":"your-store.myshopify.com",
 "occurredAt":"2026-10-09T10:00:00.000Z","data":{"rule":"R1","orderName":"31601", …}}

Verifying the signature

Compute HMAC-SHA256 of the raw request body with your signing secret and compare it to the header in constant time.

import { createHmac, timingSafeEqual } from "node:crypto";

function verify(rawBody, secret, header) {
  const expected = Buffer.from("sha256=" + createHmac("sha256", secret).update(rawBody).digest("hex"));
  const got = Buffer.from(header || "");
  return expected.length === got.length && timingSafeEqual(expected, got);
}

Delivery