What you will build
A local HTTP server that receives Arcus webhook events, verifies the signature, and logs the event type. You will then trigger a real event from the Arcus app and see it arrive.Prerequisites
- An API key with
webhooks:managescope - Node.js 18 or later (or adapt the examples to your stack)
- ngrok or similar tunnel (to expose localhost to the internet)
Step 1: Start a local server
Step 2: Expose with ngrok
https:// forwarding URL (e.g. https://abc123.ngrok-free.app).
Step 3: Register the endpoint
url must be an http or https address that is not a private or loopback address, which is why the tunnel from step 2 is needed. enabled_events is required and must not be empty: list event names, use <family>.* for a whole family (for example order.*), or * for every event. The older events field is still accepted but deprecated, so use enabled_events in new code.
Save the secret from the response. The full secret is returned when you create the endpoint, and you can read it again later with GET /v1/webhook_endpoints/{id}/secret (scope webhooks:manage), so you do not lose it if you miss it here. Store it somewhere safe either way:
Step 4: Trigger an event
In the Arcus app, create a new draft order and confirm it. Within a few seconds, your terminal should show:Step 5: Handle events safely
In production, follow these patterns:Next steps
- Read Webhooks for the full event catalog and retry behavior
- Add more event types to your subscription in Settings > Developers > Webhooks
- Set up monitoring to alert on delivery failures (Arcus makes up to 6 delivery attempts with growing delays between them)

