Docs / Webhooks

Webhooks

Get notified when an e-CF changes state.

Configuration

  1. Set webhook_url in Settings → Webhooks.
  2. (Recommended) set webhook_secret for HMAC-SHA256 signing.
  3. When an e-CF state changes, a signed POST is sent.
  4. Respond 2xx to acknowledge. Otherwise the delivery is retried up to 5 times with exponential backoff (1m, 5m, 30m, 2h, 12h).

Payload

{
  "event": "ecf.status_update",
  "internalTrackId": "uuid",
  "encf": "E310000000001",
  "estado": "aceptado",
  "dgiiCode": "0",
  "dgiiMessage": "Aceptado",
  "trackId": "dgii-track-id",
  "timestamp": "2026-04-24T12:00:00.000Z"
}

Headers

HeaderDescription
X-ECF-Tenant-IdYour tenant ID
X-ECF-EventEvent type (ecf.status_update, webhook.test)
X-ECF-Delivery-IdUnique delivery attempt ID. use for idempotency on your side
X-ECF-Signaturesha256=<hex> HMAC-SHA256 of raw body with your secret

Verify signature (Node.js)

const crypto = require('crypto');
const expected = 'sha256=' + crypto.createHmac('sha256', SECRET).update(rawBody).digest('hex');
if (!crypto.timingSafeEqual(Buffer.from(received), Buffer.from(expected))) return res.status(401).end();

Test endpoint

curl -X POST https://ecf.frandeone.com/api/webhooks/test \
  -H "Authorization: Bearer $JWT" -H "Content-Type: application/json" -d '{}'

Delivery history

curl "https://ecf.frandeone.com/api/webhooks/deliveries?status=failed" \
  -H "Authorization: Bearer $JWT"