> For the complete documentation index, see [llms.txt](https://docs.loomgate.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.loomgate.io/en/webhooks/webhook-endpoints.md).

# Set up webhooks

Create webhook endpoints, URL requirements, retries and how to handle webhooks correctly.

## Create an endpoint

In the merchant dashboard, [**Webhook**](https://app.loomgate.io/webhooks) section, add an endpoint:

* **Webhook URL**: for example `https://shop.example.com/webhooks/loomgate`.
* **Events**: choose the types you want to receive; selecting none = receive all of them.

After creating it, copy the **endpoint ID** (`we_…`): you need it to verify signatures. Each account can have up to 16 endpoints; endpoints can be edited, disabled or deleted. A disabled endpoint does not receive new events.

## URL requirements

* Must be `https://` on the default port (443), with a public **host name**: no IP address, no other port (such as `:8443`), no name that only exists inside a private network (`localhost`, `*.local`, `*.internal`…). At most 2048 characters.
* Must return a `2xx` code within **10 seconds**. Any other code, a connection error or a timeout counts as a failure.
* Redirects (3xx) are **not followed**: use the final URL.
* The route must accept requests without a login (authentication is done with the signature). If you use a web application firewall or a security plugin, open this route.

## Where webhooks come from

Webhooks leave from Loomgate's network through shared IP addresses that change over time; there is no fixed list. **Do not block or allowlist by IP address**: let the webhook route accept requests from any address and authenticate every webhook with its [signature](/en/webhooks/verify-signatures.md).

## What a delivery looks like

```http
POST /webhooks/loomgate HTTP/1.1
Content-Type: application/json
User-Agent: Loomgate-Webhooks/1.0
Loomgate-Event-Id: evt_9fK2mQ7xR4tL1vB8nC3d
Loomgate-Event-Type: payment_intent.succeeded
Loomgate-Signature: t=1790000000,kid=k1,v1=/lvIiLtH/ndQufwkco75zmDQjuagCiDFztEbB1NLT8RateCw…

{"id":"evt_9fK2mQ7xR4tL1vB8nC3d","object":"event","type":"payment_intent.succeeded","created":1790000000,"data":{"object":{…}}}
```

`Loomgate-Event-Id` and `Loomgate-Event-Type` are only there for convenience and are not signed: always take the information from the body after you [verify the signature](/en/webhooks/verify-signatures.md).

## Retries on failure

The first delivery is sent as soon as the event happens (a few seconds' delay). If it fails, Loomgate retries after:

| After attempt | Wait       |
| ------------- | ---------- |
| 1             | 30 seconds |
| 2             | 2 minutes  |
| 3             | 10 minutes |
| 4             | 1 hour     |
| 5             | 4 hours    |
| 6             | 12 hours   |
| 7             | 24 hours   |

After 8 failed attempts, the delivery is marked `failed`. See the delivery history (status, HTTP code, error) in the **Webhook** section of the dashboard.

## Handle webhooks correctly

* **Verify the signature first**, before anything else, on the raw, unprocessed body.
* **Return 2xx quickly**: record the event, then do the heavy work (sending emails, calling your inventory system…) in the background.
* **Prevent duplicate processing**: an event can arrive more than once. Store the event `id` (`evt_…`) and skip it if you have already processed it.
* **Don't rely on ordering**: events may arrive in a different order than they happened. When you need the latest state, read the object again through the API (for example `GET /partner/v1/payment_intents/{id}`).
* **Reconcile regularly**: if your server is down for longer than the retry window, use `GET /partner/v1/payment_intents` to find succeeded payments you have not recorded.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.loomgate.io/en/webhooks/webhook-endpoints.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
