Order Status Webhook Delivery
Technical design • RFC 014 • Proposed
Owner: Alex Rivera Reviewers: API + Reliability Updated: 18 June 2027
Context and Boundaries
Partners currently poll for order updates. This design adds signed event delivery to registered HTTPS endpoints. It excludes partner endpoint provisioning, historical backfills and delivery to arbitrary customer-supplied URLs.
Delivery Path
Order transaction → transactional outbox → delivery queue → worker → registered partner endpoint. A delivery record stores each attempt and its result.
| Requirement | Design response |
|---|---|
| No lost committed events | Write the outbox record in the order transaction |
| Duplicate-safe processing | Keep event_id stable across retries |
| Endpoint authenticity | Sign the raw request body with the partner secret |
| Failure isolation | Separate per-partner concurrency and delivery limits |
Event Example
{
"event_id": "evt_demo_0042",
"type": "order.shipped",
"occurred_at": "2027-06-18T14:05:00Z",
"data": {"order_id": "ord_demo_108", "status": "shipped"}
}
The identifiers and payload are illustrative. No credentials or customer information are included.