Webhooks
Clione receives webhooks from Shopify, BigCommerce and WooCommerce so product changes in your store reach Clione without a full sync. Clione registers them whenever a store's credentials are saved. A store installed through the Clione Shopify app has them registered by Shopify at install. A Shopify store connected with a permanent access token gets no webhooks; sync keeps it up to date. Every delivery is authenticated against the secret Clione holds for that store before anything in it is trusted; a delivery that fails the check is rejected with 401 and never applied.
Webhooks keep products in sync. Categories, collections and pages are updated by sync.
A product webhook only updates catalogue data: it never runs enrichment.
Shopify
Endpoint: POST /api/v1/webhooks/shopify (also accepted at POST /api/v1/shopify/webhooks).
| Topic | What Clione does |
|---|---|
products/create | Syncs the product into Clione |
products/update | Syncs the product's changes |
products/delete | Removes the product |
app/uninstalled | Deactivates the store and rolls back the signals Clione wrote |
customers/data_request | Acknowledged and logged — Clione stores no customer personal data |
customers/redact | Acknowledged and logged — nothing to erase |
shop/redact | Acknowledged and logged against the store |
Signature. The X-Shopify-Hmac-Sha256 header carries the base64-encoded HMAC-SHA256 of the raw request body. Clione computes it with the secret the store's webhooks are signed with — the client secret of the store's own Shopify app, or the Clione app's secret for a store connected through it — and compares in constant time. The store is resolved from X-Shopify-Shop-Domain (a *.myshopify.com domain; anything else is 400), and the topic from X-Shopify-Topic.
BigCommerce
Endpoint: POST /api/v1/bigcommerce/webhooks.
| Scope | What Clione does |
|---|---|
store/product/created | Syncs the product into Clione |
store/product/updated | Syncs the product's changes |
store/product/deleted | Removes the product |
Authentication. BigCommerce does not sign webhook bodies. When Clione registers a hook it sets two headers that BigCommerce sends back on every delivery:
X-Clione-Store-Id— the Clione store, cross-checked against the payload'sproducer(stores/<hash>).X-Clione-Webhook-Secret— a random secret generated for that store, compared in constant time against the one Clione holds.
An unknown store or a wrong secret is 401.
WooCommerce
Endpoint: POST /api/v1/woocommerce/webhooks?store=<store id>.
| Topic | What Clione does |
|---|---|
product.created | Syncs the product into Clione |
product.updated | Syncs the product's changes |
product.deleted | Removes the product |
Signature. The X-WC-Webhook-Signature header carries the base64-encoded HMAC-SHA256 of the raw body, signed with a per-store secret Clione sets when it registers the hook. The store comes from the store query parameter, cross-checked against X-WC-Webhook-Source. The ping WooCommerce sends when a hook is created is answered 200, so the hook is marked active.
Order events
orders/create and orders/paid (Shopify) and store/order/created and store/order/statusUpdated (BigCommerce) are verified the same way and recorded as order signals if they are delivered. Clione does not register them.
Responses
| Status | Meaning |
|---|---|
200 | Accepted. Includes topics Clione does not handle and stores that are inactive: they are acknowledged so the platform stops retrying, and ignored. |
400 | Malformed delivery: missing topic or scope, no product id, or an invalid shop domain. |
401 | The signature or secret did not verify for any store Clione holds. |
500 | Shopify app topics only: the app secret is not configured. An unsigned webhook is never accepted. |