Docs · API reference
Webhooks
Signed payloads, idempotent events, exponential retries.
Events v1
- listing.published
- listing.updated
- listing.failed
- listing.deleted
- account.connected
- account.verification_required
- account.connection_failed
- account.disconnected
- account.reauthenticated
Every envelope carries a top-level mode (test or live) alongside event, created_at and data, so you can route sandbox and production deliveries without inspecting the payload.
POST /api/v1/accounts also returns the current state immediately. Persist its job_id and poll GET /api/v1/jobs/{job_id} as a fallback when webhook delivery is delayed.
Account connection states
| Event | Meaning | Next action |
|---|---|---|
| account.connected | Credentials are valid and the account is active. | Listing actions can start. |
| account.verification_required | The marketplace requires an email/SMS code or mobile approval. | Follow verification.type, verification.channel, and next_action. |
| account.connection_failed | The attempt failed with a client-safe error code. | Follow next_action or inspect the job. |
For security, an unknown marketplace account and a wrong password can both be reported as credentials_invalid; this prevents account enumeration.
Verifying signatures
BODY=$(cat request_body)
SIGNED="$X_LISTBRIDGE_TIMESTAMP.$BODY"
SIG=$(printf '%s' "$SIGNED" | openssl dgst -sha256 -hmac "$WEBHOOK_SECRET" | awk '{print $2}')
test "sha256=$SIG" = "$X_LISTBRIDGE_SIGNATURE" || exit 1
Retry schedule
On non-2xx response, we retry at 3, 10, 30, 60, 360 and 1440 minutes. After the initial attempt and configured retries, the delivery is marked exhausted and can be replayed from the console.