Webhooks are HTTP calls (callbacks) that our server makes to yours when an important event occurs asynchronously (e.g., a quote was approved or paid).
Registering an endpoint
To receive webhooks, expose a POST route on your server (e.g., https://api.yourcompany.com/webhooks/cord).
- Turn on Developer mode (the switch at the bottom of the Settings index) and open the Webhooks tab in the Developers dock, the bar at the bottom of the screen.
- Add your URL and save. The signing secret is shown only once: store it.
- Select which events to subscribe to.
Available events
Cord emits quote lifecycle events and, separately, events for the invoice as its own object (see Invoicing and the API):
quote.sent— sent to the customer.quote.viewed— the customer opened it.quote.approved— the customer approved it.quote.rejected— the customer rejected it.quote.updated— it was edited and resent.quote.expired— it expired without a response.quote.deleted— a draft was deleted.quote.paid— it was paid in full.payment.partial— a deposit, balance, or installment was collected without covering the full total.payment.failed— a recurring charge failed.invoice.finalized,invoice.sent,invoice.paid,invoice.payment_failed,invoice.voided,invoice.marked_uncollectible,invoice.overdue— lifecycle of an invoice created as its own resource via/api/v1/facturas.quote.created,quote.approval_requested,quote.approval_decided,quote.comment_added— a quote was created, an internal approval was requested or decided, or someone wrote in the conversation.client.created,client.updated,client.deleted,product.created,product.updated,product.deleted— changes to your client directory and catalog.task.created,task.completed,promise.created,promise.kept,promise.broken— tasks and payment promises.dispute.created,dispute.closed,refund.succeeded,refund.failed,payout.paid,payout.failed,account.updated— disputes, refunds, payouts, and changes to your payments account.
If you don’t select any event, the endpoint receives all of them, including ones added later.
The body is JSON: { "id": "evt_...", "event": "quote.paid", "created_at": "...", "data": { "id", "folio", "status", "moneda", "total", "cliente", "cliente_id", "link_publico" } }. The event’s id is stable across retries and a manual redelivery from the dashboard — use it to deduplicate on your side.
Signature verification
Always validate the signature to ensure the event comes from Cord. Every delivery includes X-Cord-Signature-V1 (with a timestamp, replay protection) and, for backward compatibility, the legacy X-Cord-Signature (no timestamp). The event name travels in X-Cord-Event and its stable id in X-Cord-Event-Id/Idempotency-Key. On Node, the @flouviahq/elements/server package validates both forms for you (CordWebhooks.constructEvent); if you’d rather verify it by hand in any language, see the verification code.
Retries and inspection
Each endpoint keeps a delivery log (status, latency, and response for every attempt). If a delivery fails, you can redeliver it from the dashboard, and use the Test button to send a test event.