Skip to main content

Webhooks

Clione receives webhooks from Shopify, BigCommerce and WooCommerce so product changes in your store reach Clione without a full sync. Clione registers them whenever a store's credentials are saved. A store installed through the Clione Shopify app has them registered by Shopify at install. A Shopify store connected with a permanent access token gets no webhooks; sync keeps it up to date. Every delivery is authenticated against the secret Clione holds for that store before anything in it is trusted; a delivery that fails the check is rejected with 401 and never applied.

Webhooks keep products in sync. Categories, collections and pages are updated by sync.

A product webhook only updates catalogue data: it never runs enrichment.

Shopify​

Endpoint: POST /api/v1/webhooks/shopify (also accepted at POST /api/v1/shopify/webhooks).

TopicWhat Clione does
products/createSyncs the product into Clione
products/updateSyncs the product's changes
products/deleteRemoves the product
app/uninstalledDeactivates the store and rolls back the signals Clione wrote
customers/data_requestAcknowledged and logged — Clione stores no customer personal data
customers/redactAcknowledged and logged — nothing to erase
shop/redactAcknowledged and logged against the store

Signature. The X-Shopify-Hmac-Sha256 header carries the base64-encoded HMAC-SHA256 of the raw request body. Clione computes it with the secret the store's webhooks are signed with — the client secret of the store's own Shopify app, or the Clione app's secret for a store connected through it — and compares in constant time. The store is resolved from X-Shopify-Shop-Domain (a *.myshopify.com domain; anything else is 400), and the topic from X-Shopify-Topic.

BigCommerce​

Endpoint: POST /api/v1/bigcommerce/webhooks.

ScopeWhat Clione does
store/product/createdSyncs the product into Clione
store/product/updatedSyncs the product's changes
store/product/deletedRemoves the product

Authentication. BigCommerce does not sign webhook bodies. When Clione registers a hook it sets two headers that BigCommerce sends back on every delivery:

  • X-Clione-Store-Id — the Clione store, cross-checked against the payload's producer (stores/<hash>).
  • X-Clione-Webhook-Secret — a random secret generated for that store, compared in constant time against the one Clione holds.

An unknown store or a wrong secret is 401.

WooCommerce​

Endpoint: POST /api/v1/woocommerce/webhooks?store=<store id>.

TopicWhat Clione does
product.createdSyncs the product into Clione
product.updatedSyncs the product's changes
product.deletedRemoves the product

Signature. The X-WC-Webhook-Signature header carries the base64-encoded HMAC-SHA256 of the raw body, signed with a per-store secret Clione sets when it registers the hook. The store comes from the store query parameter, cross-checked against X-WC-Webhook-Source. The ping WooCommerce sends when a hook is created is answered 200, so the hook is marked active.

Order events​

orders/create and orders/paid (Shopify) and store/order/created and store/order/statusUpdated (BigCommerce) are verified the same way and recorded as order signals if they are delivered. Clione does not register them.

Responses​

StatusMeaning
200Accepted. Includes topics Clione does not handle and stores that are inactive: they are acknowledged so the platform stops retrying, and ignored.
400Malformed delivery: missing topic or scope, no product id, or an invalid shop domain.
401The signature or secret did not verify for any store Clione holds.
500Shopify app topics only: the app secret is not configured. An unsigned webhook is never accepted.