Skip to main content

What you will build

A local HTTP server that receives Arcus webhook events, verifies the signature, and logs the event type. You will then trigger a real event from the Arcus app and see it arrive.

Prerequisites

  • An API key with webhooks:manage scope
  • Node.js 18 or later (or adapt the examples to your stack)
  • ngrok or similar tunnel (to expose localhost to the internet)

Step 1: Start a local server

Step 2: Expose with ngrok

Copy the https:// forwarding URL (e.g. https://abc123.ngrok-free.app).

Step 3: Register the endpoint

url must be an http or https address that is not a private or loopback address, which is why the tunnel from step 2 is needed. enabled_events is required and must not be empty: list event names, use <family>.* for a whole family (for example order.*), or * for every event. The older events field is still accepted but deprecated, so use enabled_events in new code. Save the secret from the response. The full secret is returned when you create the endpoint, and you can read it again later with GET /v1/webhook_endpoints/{id}/secret (scope webhooks:manage), so you do not lose it if you miss it here. Store it somewhere safe either way:
Restart your server with the real secret.

Step 4: Trigger an event

In the Arcus app, create a new draft order and confirm it. Within a few seconds, your terminal should show:

Step 5: Handle events safely

In production, follow these patterns:

Next steps

  • Read Webhooks for the full event catalog and retry behavior
  • Add more event types to your subscription in Settings > Developers > Webhooks
  • Set up monitoring to alert on delivery failures (Arcus makes up to 6 delivery attempts with growing delays between them)