Skip to main content

Signing

If the merchant has configured a webhook secret, each request carries:
  • X-Novacrust-Signature — HMAC-SHA256 of ${timestamp}.${JSON.stringify(payload)}, using the merchant’s webhook secret.
  • X-Novacrust-Timestamp — the timestamp used in the signature above.
If no webhook secret is configured, requests are sent unsigned.

Gift Cards

Gift card webhooks use a flat envelope — no data wrapper, event sits alongside the other fields directly.

Purchase (business buying a gift card) — GIFT_CARD_PURCHASE_SUCCESS / GIFT_CARD_PURCHASE_FAILED

Note: as delivered live today, GIFT_CARD_PURCHASE_FAILED carries a smaller field set than GIFT_CARD_PURCHASE_SUCCESS — it omits amount, quantity, total_amount, currency, and recipient_email. A manually re-triggered delivery of the same failed event currently sends the fuller field set instead. Integrators should treat those five fields as optional/absent on a failed purchase event until this is reconciled.

Sale (business selling a gift card to Novacrust) — GIFT_CARD_SALE_SUCCESS / GIFT_CARD_SALE_FAILED

metadata is a passthrough of the order’s own metadata — its shape is not fixed and depends on the order/provider.

Field reference