Webhooks
Receive a signed JSON POST from WRMS Pro whenever customers, vehicles, work orders, quotes, payments, inspections, stock or observations change.
A webhook tells another system about something that just happened in WRMS Pro. You give WRMS Pro a URL and choose events; WRMS Pro sends an HTTP POST with a JSON body to that URL each time one of them occurs.
Create a webhook
http:// or https://; use HTTPS.whsec_). Copy it now — it is shown only once. Store it where your endpoint can read it, such as an environment variable.ping.test event and check your endpoint receives it.The request
POST /your/endpoint HTTP/1.1
Content-Type: application/json
User-Agent: WRMS-Pro-Webhooks/1.0
X-WRMS-Event: service.status
X-WRMS-Delivery: <delivery id>
X-WRMS-Signature: t=1790000000000,v1=5f1c…e9
X-WRMS-Attempt: 1| Header | Meaning |
|---|---|
X-WRMS-Event | The event name, for example payment.create. |
X-WRMS-Delivery | A unique ID for this delivery. The same event retried keeps the same delivery ID — use it to ignore duplicates. |
X-WRMS-Signature | t= timestamp (milliseconds since 1970) and v1= HMAC-SHA256 signature. See Verifying signatures. |
X-WRMS-Attempt | 1 for the first attempt, higher on retries. |
The body
Every event uses the same envelope:
{
"id": "evt_…",
"event": "service.status",
"createdAt": "2026-09-25T01:30:00.000Z",
"organizationId": "…",
"entity": "service",
"entityId": "…",
"message": null,
"userId": "…",
"data": { }
}| Field | Type | Meaning |
|---|---|---|
id | string | Unique event ID. |
event | string | The event name. |
createdAt | string (ISO 8601, UTC) | When the event happened. |
organizationId | string | The workshop the event belongs to. |
entity | string or null | The kind of record, for example customer, vehicle, service (a work order), quote. |
entityId | string or null | The record's WRMS Pro ID. |
message | string or null | A human-readable summary, when there is one. |
userId | string or null | The WRMS Pro user who made the change, or null for automatic changes. |
data | object | Event-specific details. |
The contents of data vary by event and are not documented field by field. Treat data as optional and read it defensively; use entity and entityId as the reliable reference to the record. The sample payloads in the settings screen are illustrations, not exact copies.
Respond quickly
Return any 2xx status within 10 seconds to acknowledge the event. Do slow work (calling other APIs, writing to a database) after responding, or in a queue. Anything else — an error status, a redirect or a timeout — counts as a failure and is retried. See Errors and retries.
Manage webhooks
In Settings → Webhooks each webhook shows whether it is Healthy or has recent failures, when it last delivered, and how many deliveries it has made.
- Deliveries — the last 50 attempts, with status, attempt number and next retry time. You can retry a failed delivery from here.
- Rotate signing secret — issues a new secret. The old one stops working immediately, so update your endpoint straight away.
- Turn a webhook off and on with its switch, or Delete it.
Rules WRMS Pro applies to endpoints
- URLs that point to private, internal or local network addresses are refused.
- Redirects are not followed.
- Request bodies are limited to 256 KB.
Still need help?
Email support@wrmspro.com or use the contact form. Signed-in users can also send a request from Settings → Support.