Webhooks for new orders
A webhook sends each new order, and each change to it, to your own system as a signed JSON message. You give Menuthere an HTTPS address and a secret, then verify the signature on each request. A test button and a delivery log let you check it works.
- Where
- Set up by Menuthere support
- Plan
- The dashboard does not lock webhooks by plan.
- Time
- 15 min
- Updated
Set up a webhook
Step 1: Send support your address
Webhooks are not in the dashboard yet, so Menuthere support sets them up. Send support the address that will receive orders. It must start with https:// and be reachable from the internet. Addresses such as localhost or a private network cannot be called.
Step 2: Keep the signing secret
Support switches order webhooks on and gives you a signing secret. Keep it on your server only. You use it to check each request really came from Menuthere.
Step 3: Ask for a test event
Ask support to send a test event. It posts a sample order.created to your address, and the result shows Delivered with your endpoint's reply code, or what went wrong.
What Menuthere sends
| Event | Sent when |
|---|---|
| order.created | An order is placed. |
| order.status_updated | An order's status changes, for example accepted, food ready or completed. |
| payment.status_updated | An order is marked paid, or its payment method changes. |
| delivery.status_updated | A rider is assigned or the delivery state changes. |
| Header | Value |
|---|---|
| x-menuthere-event | The event name. |
| x-menuthere-timestamp | Unix time in seconds, set again on each attempt. |
| x-menuthere-signature | A hex HMAC-SHA256 of the raw request body, made with your secret. |
The body is an envelope with event, a unique id, created_at and data. A test event also carries "test": true, so skip it in your kitchen. For order.created, data holds the fields below.
| Field | Contents |
|---|---|
| order_id, order_number | The order's ID and the number shown to your team. |
| status, type, placed_at, currency | Current status, order type, time placed and currency. |
| totals | subtotal, delivery_charge, packing_charge, gst, discount, grand_total. |
| customer | name, phone, address. |
| table | Table number and name for a table order, otherwise empty. |
| items | Each line: name, quantity, unit_price, total_price, variant, notes. |
| notes, payment | The customer's note, and the payment method and whether it is_paid. |
Verifying and reliability
- Check the signature against the raw body. Parsing and re-encoding the JSON changes spacing and order, and the signature will not match.
- Be idempotent. The same id can arrive twice. Use it to avoid a second kitchen ticket.
- Reply with a 2xx quickly. Menuthere waits 8 seconds per attempt and tries up to three times, after 1.5 seconds and then 5 seconds. A timeout, a 5xx, a 408 or a 429 is retried. Any other 4xx is taken as a deliberate no and stops.
- Check Recent deliveries. The panel lists attempts from the last 24 hours, newest first, with the reply code and time. Each retry is its own row.
Questions
Can I point it at a server on my own network?
Can I tell my POS the order was accepted?
Is the delivery log kept forever?
Related
Can't find it? Email [email protected] or chat with us, 9 AM – 9 PM.Help centerPricingmenuthere.com
