Receive webhook
POST/api/webhooks/square
Public endpoint — no bearer required. Square posts here for every subscribed event.
Required header: X-Square-HmacSha256-Signature (Square signs notification_url + raw_body with the subscription's signature key; verified per-instance).
Handled event families: order.* (refetches the order and promotes), refund.* (recorded in v1; sales-credit reconciliation lands in a follow-up), inventory.* / catalog.* (marked ignored — served by the scheduled sync commands).
Request
Responses
- 200
- 401
- 403
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Validation failed — the body is a field → messages map (Laravel shape) or the platform envelope with a stable machine-readable code. Fix the payload and resubmit.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.