Webhooks
On the Pro plan, DockGuard can POST events to an https endpoint you choose (DockGuard → Integrations). Deliveries are signed so you can verify they came from DockGuard.
Events
incident.opened— a new problem was detected (data.ruleR1–R6, R8,data.orderName).incident.resolved— the problem cleared on a later check.connection.broken— DockGuard could not reach Mailstep twice in a row (R7).fix.applied— a fix ran from DockGuard (data.fixF1 add tracking, F2 re-send).
Saving the endpoint sends a test incident.opened with data.test = true.
Request
POST your-endpoint
Content-Type: application/json
X-DockGuard-Event: incident.opened
X-DockGuard-Delivery: clx… (unique, use it to deduplicate)
X-DockGuard-Signature: sha256=<hex>
{"id":"clx…","event":"incident.opened","shop":"your-store.myshopify.com",
"occurredAt":"2026-10-09T10:00:00.000Z","data":{"rule":"R1","orderName":"31601", …}}
Verifying the signature
Compute HMAC-SHA256 of the raw request body with your signing secret and compare it to the header in constant time.
import { createHmac, timingSafeEqual } from "node:crypto";
function verify(rawBody, secret, header) {
const expected = Buffer.from("sha256=" + createHmac("sha256", secret).update(rawBody).digest("hex"));
const got = Buffer.from(header || "");
return expected.length === got.length && timingSafeEqual(expected, got);
}
Delivery
- Answer with any 2xx within 10 seconds. Redirects are not followed.
- Failed deliveries are retried after 1 min, 5 min, 30 min, 2 h, 6 h and 24 h, then dropped.
- After 20 failed deliveries in a row the endpoint is paused; resume it in DockGuard → Integrations.
- Delivery is at least once: deduplicate on
X-DockGuard-Delivery.