> For the complete documentation index, see [llms.txt](https://docs.partssource.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.partssource.com/webhooks/quickstart.md).

# Quickstart

From nothing to a verified, deduplicated webhook handler

From nothing to a verified, deduplicated webhook handler in five steps.

## 1. Register your endpoint

Endpoints are registered through the PartsSource integration team. You receive an endpoint secret per environment; store it in configuration, never in code.

## 2. Receive the raw body

Your framework must expose the exact bytes sent: the signature covers the body exactly as sent, so JSON middleware must not run before verification.

## 3. Verify and acknowledge

The normative signature specification lives in [Verifying Deliveries](/webhooks/verifying-deliveries.md); these samples implement it.

{% tabs %}
{% tab title="Node" %}

```javascript
const express = require('express');
const crypto = require('crypto');
const app = express();

app.post('/webhooks/partssource',
  // Keep the raw bytes. Do not use express.json() on this route:
  // the signature covers the body exactly as sent.
  express.raw({ type: 'application/json' }),
  (req, res) => {
    const signature = req.headers['x-ps-signature'] ?? '';
    const timestamp = req.headers['x-ps-timestamp'] ?? '';

    // Reject deliveries older than five minutes (replay protection).
    if (Math.abs(Date.now() / 1000 - Number(timestamp)) > 300) {
      return res.status(401).end();
    }

    // Verify HMAC-SHA256 over "<timestamp>.<raw body>" in constant time.
    const expected = crypto
      .createHmac('sha256', process.env.PS_WEBHOOK_SECRET)
      .update(`${timestamp}.${req.body}`)
      .digest('hex');
    const a = Buffer.from(signature);
    const b = Buffer.from(expected);
    if (a.length !== b.length || !crypto.timingSafeEqual(a, b)) {
      return res.status(401).end();
    }

    // Acknowledge immediately; process asynchronously.
    res.status(200).end();
    queue.push(JSON.parse(req.body));
  });
```

{% endtab %}

{% tab title="C#" %}

```csharp
app.MapPost("/webhooks/partssource", async (HttpRequest req) =>
{
    using var reader = new StreamReader(req.Body);
    var body = await reader.ReadToEndAsync(); // raw body, before any model binding

    var signature = req.Headers["X-PS-Signature"].ToString();
    var timestamp = req.Headers["X-PS-Timestamp"].ToString();

    if (!long.TryParse(timestamp, out var ts) ||
        Math.Abs(DateTimeOffset.UtcNow.ToUnixTimeSeconds() - ts) > 300)
        return Results.Unauthorized();

    var secret = Environment.GetEnvironmentVariable("PS_WEBHOOK_SECRET")!;
    using var hmac = new HMACSHA256(Encoding.UTF8.GetBytes(secret));
    var expected = Convert.ToHexString(
        hmac.ComputeHash(Encoding.UTF8.GetBytes($"{timestamp}.{body}"))).ToLowerInvariant();

    if (!CryptographicOperations.FixedTimeEquals(
            Encoding.UTF8.GetBytes(expected), Encoding.UTF8.GetBytes(signature)))
        return Results.Unauthorized();

    await queue.EnqueueAsync(body); // process asynchronously
    return Results.Ok();
});
```

{% endtab %}

{% tab title="Python" %}

```python
@app.post("/webhooks/partssource")
def webhook():
    raw = request.get_data()  # raw bytes, before any JSON parsing
    signature = request.headers.get("X-PS-Signature", "")
    timestamp = request.headers.get("X-PS-Timestamp", "0")

    if abs(time.time() - float(timestamp)) > 300:
        abort(401)

    expected = hmac.new(
        os.environ["PS_WEBHOOK_SECRET"].encode(),
        f"{timestamp}.".encode() + raw,
        hashlib.sha256,
    ).hexdigest()

    if not hmac.compare_digest(expected, signature):
        abort(401)

    queue.enqueue(raw)  # process asynchronously
    return "", 200
```

{% endtab %}
{% endtabs %}

## 4. Deduplicate

Delivery is at-least-once: your endpoint will occasionally receive the same event twice. Store a composite key and skip repeats — the key works for every event type.

```javascript
const key = `${event.event_type}:${event.order_id}:${event.line_item_id}:${event.occurred_at}`;
if (await store.exists(key)) return; // duplicate delivery, already processed
await store.put(key, { ttl: '48h' });
```

## 5. Process asynchronously

Return 2xx within 10 seconds; do the work off the request thread. The full delivery contract — headers, ordering, retries — is in [Delivery & Retries](https://docs.partssource.com/webhooks-customer/delivery-and-retries). If deliveries fail, start with [Troubleshooting](/webhooks/troubleshooting.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.partssource.com/webhooks/quickstart.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
