Webhooks: events to your own URL

Register an HTTPS endpoint, choose events, verify the signature on every delivery, and understand retries.

Register an HTTPS endpoint and Ordina sends each event to it the moment it happens, signed so you can trust it.

  1. Add an endpointYour HTTPS URL and the events.
  2. Save the secretShown once.
  3. Verify signaturesX-Ordina-Signature.
  4. Answer 2xxWithin 10 seconds.

Adding an endpoint

  1. Open Integration, then Webhooks, and add your HTTPS URL.
  2. Pick the events it should receive.
  3. Copy the signing secret. It is shown once; if you lose it, remove the endpoint and add it again.

Events

booking.created, booking.rescheduled, booking.cancelled, booking.completed, order.created, order.preparing, order.ready, order.dispatched, order.fulfilled, order.cancelled, payment.received, lead.created, review.created.

Verifying a delivery

Every delivery has a header:

X-Ordina-Signature: t=1727700000,v1=5f2c...e9a1

v1 is the hex HMAC-SHA256 of the timestamp, a dot, and the raw request body, keyed with your signing secret. Recompute it and compare; reject old timestamps to stop replays.

import crypto from "node:crypto";

function verify(rawBody, header, secret) {
  const parts = Object.fromEntries(header.split(",").map((p) => p.split("=")));
  const expected = crypto.createHmac("sha256", secret)
    .update(`${parts.t}.${rawBody}`, "utf8").digest("hex");
  const fresh = Math.abs(Date.now() / 1000 - Number(parts.t)) < 300;
  return fresh && crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(parts.v1));
}

Use the raw body exactly as received, before any JSON parsing.

Delivery and retries

  • Delivered means any 2xx answer within 10 seconds. Anything else, including a redirect, is a failure.
  • Failures are retried after 1, 5, 30, 120 and 720 minutes: six attempts over about 15 hours. Then the delivery is marked failed; you can see it in the endpoint's history.
  • Webhooks are part of Pro and Business. If your plan lapses, events stop until it is active again.

You can also manage endpoints from code: GET and POST https://www.useordina.com/api/v1/webhooks with an API key.

Did this answer it?If not, write to help@useordina.com with your handle, or contact us. A person replies.
Contact us