Payments
Square Webhooks
Commerce platform for payments, online stores, and business management. Receive events for payments, orders, and inventory.
Connecting Square to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Square. Then:
- 1Go to Square Developer Dashboard → Applications → Your App
- 2Navigate to Webhooks and click "Add subscription"
- 3Paste your Hookbase ingest URL and select event types
- 4Copy the Signature Key and add it to your Hookbase source signing secret
Signature verification
Square signs its webhooks with HMAC-SHA256 in x-square-hmacsha256-signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Square can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Square Developer Dashboard → Applications → Webhooks → Signature Key.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Square event types
6 of the events people route most often. Hookbase accepts every event Square sends, whether or not it is listed here.
payment.completed
A payment was completed
payment.updated
A payment was updated
order.created
A new order was created
order.updated
An order was updated
invoice.published
An invoice was published
inventory.count.updated
Inventory count was updated
What a Square webhook looks like
A payment.completed payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"merchant_id": "MERCHANT_ID_123",
"type": "payment.completed",
"event_id": "evt_123456",
"created_at": "2024-01-15T10:30:00Z",
"data": {
"type": "payment",
"id": "pay_123456",
"object": {
"payment": {
"id": "pay_123456",
"amount_money": {
"amount": 1000,
"currency": "USD"
},
"status": "COMPLETED"
}
}
}
}Start receiving Square webhooks
Create a source, paste the URL into Square, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free