Documentation / Webhooks

Webhooks และ event delivery

ตั้งการส่ง statuses และ events ระหว่าง systems ให้เชื่อถือได้ ตั้งแต่สร้าง message และตรวจ signature ไปจนถึง acknowledgement, redelivery และ error control

เปิด Security section
Events
statuses และ changes
Signature
authentication check
Retries
redelivery
Control
history และ diagnostics
Event path

จาก creation ถึง acknowledgement

01
สร้าง event

กำหนด ID, type, time, object, status และ related data

02
Sign และส่ง

ส่ง event ผ่าน HTTPS พร้อม signature และ timeout ที่จำกัด

03
Acknowledge receipt

หลังตรวจสอบ ให้เก็บ event อย่างปลอดภัยแล้วส่ง successful HTTP response อย่างรวดเร็ว

04
Retry เมื่อเกิด error

Retry delivery ด้วย backoff และเก็บ undelivered events ไว้วิเคราะห์

ภาพรวม

Webhook แจ้งการเปลี่ยนแปลงของ state

Sender อาจ redeliver ดังนั้น receiver ต้องตรวจ source, acknowledge และ apply event แต่ละรายการเพียงครั้งเดียว

Event

Record การเปลี่ยนแปลงของ payment, game session, KYC check, bonus, player profile หรือ object อื่น

Acknowledgement

Receiver ส่ง successful HTTP response หลังตรวจและเก็บ event อย่างปลอดภัย

Recovery

Redelivery และ reconciliation ช่วยกู้ข้อมูลหลัง system ใด system หนึ่งไม่พร้อมชั่วคราว

Event payload

Event ควรมีข้อมูลอะไรบ้าง

Payload format แบบเดียวช่วยให้ verification, routing, duplicate protection และรองรับ event types ต่าง ๆ ง่ายขึ้น

Event ID

Unique value ที่ระบบใช้รู้ว่าเป็น redelivery และค้น processing history

Event type

ชื่อที่ชัดเจนและคงที่ซึ่งระบุการเปลี่ยนแปลงที่เกิดขึ้นและวิธี processing

Creation time

วันที่และเวลาที่ event ถูกสร้างใน format และ timezone ที่ตกลงกัน

Related object

Type และ ID ของ payment, player, round, application, bonus หรือ object อื่น

Schema version

Version number ช่วยเปลี่ยน payload structure อย่างปลอดภัยโดยไม่กระทบ integrations ที่ทำงานอยู่

Operation correlation

ID ของ original request, transaction, session หรือ chain ของ related actions

Context

Brand, project, market, environment, provider และข้อมูลอื่นที่จำเป็นต่อ routing

Event data

ชุด fields ขั้นต่ำสำหรับประมวลผล change หรือทำ API request ต่อ

Signature และ verification

ตรวจ authenticity และ integrity ของ event

ก่อนเปลี่ยนข้อมูล receiver ตรวจ secure connection, signature, creation time และ unique event ID

01

รับ raw message

ตรวจ signature จาก raw request body ก่อนเปลี่ยน JSON format

02

ตรวจเวลา

ปฏิเสธ request หาก event time อยู่นอกช่วงที่อนุญาต

03

ตรวจ signature

ใช้ shared secret และ HMAC หรือ digital signature algorithm ที่ตกลงกัน

04

ตรวจ identifier

ยืนยันว่า event ยังไม่ถูก apply และเก็บ verification result

Delivery และ retries

HTTP responses และ redelivery

Sender ต้องแยก successful receipt, temporary error และ permanent rejection ส่วน receiver ต้องตอบเร็วและชัดเจน

Successful HTTP response

ยืนยันว่า event ถูกตรวจและเก็บอย่างปลอดภัยสำหรับ processing ต่อ

Limited wait

อย่าทำ processing ที่ใช้เวลานานก่อนตอบ sender — ให้เก็บ event ก่อน

Redelivery

Retry delivery เมื่อเกิด temporary network error, unavailability หรือไม่มี response

Backoff

เพิ่มช่วงห่างระหว่าง attempts ทีละขั้น เพื่อไม่สร้างโหลดเพิ่ม

Undelivered event queue

เมื่อ attempts หมด ให้เก็บ event ไว้สำหรับ diagnostics และ manual processing

Manual replay

Operator สามารถ resend event ที่เลือกโดยไม่สร้าง operation ใหม่

Delivery monitoring

ติดตามจำนวน attempts, responses, last error และ next delivery time

Alerts

แจ้งทีมเมื่อ errors เพิ่ม attempts หมด หรือมี events ค้างใน queue

Event processing

Duplicate protection และ status ordering

Receiver ต้องไม่สมมติว่าจะได้รับเพียงครั้งเดียวหรือเรียงลำดับเสมอ

Apply once

เก็บ event ID ก่อนเปลี่ยนข้อมูล
Acknowledge repeated event โดยไม่ debit, credit หรือเปลี่ยนข้อมูลซ้ำ
เชื่อม event กับ object และ current state
เก็บ event และ business change เป็น atomic/consistent operation เดียว

Order และ freshness

เปรียบเทียบ time, sequence number หรือ event version
อย่าย้อน object ไป stale state เมื่อ event มาช้า
อนุญาตเฉพาะ valid status transitions
หากไม่แน่ใจ ให้ขอ current object state ผ่าน API
Testing

สิ่งที่ต้องตรวจสอบก่อน launch

ทดสอบ successful delivery, invalid signature, duplicates, slow response, out-of-order events และ failure recovery

Invalid signature

Modified message, unknown key, expired timestamp และ unsupported algorithm

Redelivery

Event เดิมเข้ามาหลายครั้งทั้งก่อนและหลัง processing เสร็จ

Slow response

Receiver ตอบช้าเกินไป connection หลุด หรือ acknowledgement ไม่ถึง sender

Out-of-order events

Final status มาก่อน intermediate status และ old event มาหลัง new event

Unavailable endpoint

ทดสอบ HTTP 5xx, DNS, TLS, rate limits และ attempts exhausted

Delivery history

ค้นหา attempts, responses, errors และ manual replay result ทั้งหมดได้จาก event ID

Checklist ก่อน launch

Production delivery เปิดหลังตรวจ security, duplicate protection, retries และ error control

Test และ production ใช้ endpoints และ signing secrets ต่างกัน
ตรวจ signature จาก raw message พร้อม creation time
เก็บ event ID และใช้ป้องกัน operation จากการทำซ้ำ
Receiver ส่ง successful HTTP response อย่างรวดเร็วหลังเก็บ event
ตั้ง retries, backoff และ manual replay แล้ว
Support team เข้าถึง delivery history และค้นด้วย ID ได้

ต้องการตั้ง reliable event delivery ไหม

ส่งรายการ events, receiving endpoints และ status-change rules มาให้ APIACE จะช่วยกำหนด payload, signature verification, redelivery และ error control