E-commerce
BigCommerce Webhooks
Enterprise e-commerce platform. Receive events for orders, products, customers, and carts.
Connecting BigCommerce to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into BigCommerce. Then:
- 1Use the BigCommerce API to create webhooks (POST /v3/hooks)
- 2Set the destination to your Hookbase ingest URL
- 3Specify the scope (e.g., store/order/created)
- 4Note: BigCommerce sends lightweight payloads — use the API to fetch full details
Signature verification
BigCommerce signs its webhooks with HMAC-SHA256 in X-Webhook-Signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if BigCommerce can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at The client secret from your BigCommerce API account.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
BigCommerce event types
8 of the events people route most often. Hookbase accepts every event BigCommerce sends, whether or not it is listed here.
store/order/created
A new order was placed
store/order/updated
An order was updated
store/product/created
A product was created
store/product/updated
A product was updated
store/customer/created
A new customer registered
store/cart/created
A shopping cart was created
store/cart/converted
A cart was converted to an order
store/shipment/created
A shipment was created
What a BigCommerce webhook looks like
A store/order/created payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"scope": "store/order/created",
"store_id": "1001234",
"data": {
"type": "order",
"id": 250
},
"hash": "abc123def456",
"created_at": 1678901234,
"producer": "stores/abc123"
}Start receiving BigCommerce webhooks
Create a source, paste the URL into BigCommerce, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free