Signing
If the merchant has configured a webhook secret, each request carries:X-Novacrust-Signature— HMAC-SHA256 of${timestamp}.${JSON.stringify(payload)}, using the merchant’s webhook secret.X-Novacrust-Timestamp— the timestamp used in the signature above.
Gift Cards
Gift card webhooks use a flat envelope — nodata wrapper, event sits alongside the other fields directly.
Purchase (business buying a gift card) — GIFT_CARD_PURCHASE_SUCCESS / GIFT_CARD_PURCHASE_FAILED
Note: as delivered live today,GIFT_CARD_PURCHASE_FAILEDcarries a smaller field set thanGIFT_CARD_PURCHASE_SUCCESS— it omitsamount,quantity,total_amount,currency, andrecipient_email. A manually re-triggered delivery of the same failed event currently sends the fuller field set instead. Integrators should treat those five fields as optional/absent on a failed purchase event until this is reconciled.
Sale (business selling a gift card to Novacrust) — GIFT_CARD_SALE_SUCCESS / GIFT_CARD_SALE_FAILED
metadata is a passthrough of the order’s own metadata — its shape is not fixed and depends on the order/provider.

