{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-echosync-webhooks/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Echo Webhooks"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"echo-webhooks","__idx":0},"children":["Echo Webhooks"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Echo delivers shipment events to your HTTPS endpoint as HTTP POST requests with JSON payloads. Every request is signed with HMAC-SHA256 so you can verify it genuinely came from Echo."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"webhook-event-types","__idx":1},"children":["Webhook Event Types"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Echo publishes two webhook event types. Which you receive depends on your role with Echo:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Event"},"children":["Event"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Who receives it"},"children":["Who receives it"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"What it delivers"},"children":["What it delivers"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Load Tracking / Status Update"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Customers (shippers)"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Status and geo-location tracking events for your loads"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Available Load Notification"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Carriers"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Loads available for booking (posted, updated, and cancelled)"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Everything in these pages, including registration, security, delivery, and retries, works identically for both; full payload schemas are in the API Reference."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"the-two-secrets-you-provide-read-this-first","__idx":2},"children":["The Two Secrets You Provide: Read This First"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Webhook security involves two independent mechanisms, and you create both:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A required ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Signing Secret"]}," that Echo signs payloads with so you can verify them."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Optional but recommended ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["endpoint authentication"]}," that Echo presents so your endpoint accepts the request."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Each protects something different; understanding the difference is the single most important part of onboarding."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":""},"children":[]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Signing Secret"},"children":["Signing Secret"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Endpoint Authentication"},"children":["Endpoint Authentication"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Required?"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Yes"]},": every webhook integration must have one"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Optional, but strongly recommended"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Who creates it"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["You do."]}," You invent the value and give it to Echo during registration. Echo never assigns it."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["You do. You give Echo the credentials your endpoint expects."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["What it does"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Echo signs every payload with it. You recompute the signature to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["prove the request came from Echo"]}," and wasn't tampered with."]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Echo presents these credentials so ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["your endpoint (or gateway) will accept the inbound request"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["How it's used"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["HMAC-SHA256 signature in the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["X-Echo-Hmac-SHA256"]}," header"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["API key header, Basic Auth, OAuth 2.0 bearer token, and/or custom headers"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Common mistake:"]}," configuring an API key or OAuth and skipping the Signing Secret. They are not alternatives: endpoint authentication gets Echo's request through your front door, while the Signing Secret is how you verify who sent it. The Signing Secret is always required."]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Naming notes:"]}," Earlier versions of this documentation called the Signing Secret the \"Client Secret.\" It is the same thing. It is ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["not"]}," related to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client_secret"]}," field in an OAuth 2.0 configuration; that is a separate credential you may optionally provide for endpoint authentication."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-onboarding-works","__idx":3},"children":["How Onboarding Works"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Step"},"children":["Step"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"What happens"},"children":["What happens"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["1. Prepare"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Stand up an HTTPS endpoint, create your Signing Secret, and decide on optional endpoint authentication."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Register"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Email your details to Echo's Technical Integrations team."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Validate"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Echo sends test payloads to your testing endpoint; you verify signatures and responses."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["4. Go live"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["After successful validation, Echo activates your production endpoint."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The full walkthrough is in ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/echosync-webhooks/getting-started"},"children":["Onboarding & Registration"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"documentation-map","__idx":4},"children":["Documentation Map"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Page"},"children":["Page"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"What it covers"},"children":["What it covers"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/echosync-webhooks/getting-started"},"children":["Onboarding & Registration"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Prerequisites, creating your Signing Secret, registration, validation testing, going to production"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/echosync-webhooks/technical-implementation"},"children":["Receiving & Verifying Webhooks"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["What a request looks like, verifying the signature (with code examples), endpoint authentication, implementation best practices"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/echosync-webhooks/reliability"},"children":["Delivery, Retries & Health"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Retry schedule, failure threshold, deregistration, monitoring"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/echosync-webhooks/quick-reference"},"children":["Quick Reference"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["All technical specifications on one page"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["API Reference"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Full webhook payload schemas"]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"getting-support","__idx":5},"children":["Getting Support"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Contact Echo's Technical Integrations team with:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["X-Echo-Webhook-Id"]}," values from your logs"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Relevant timestamps and error details"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A clear description of the issue"]}]}]},"headings":[{"value":"Echo Webhooks","id":"echo-webhooks","depth":1},{"value":"Webhook Event Types","id":"webhook-event-types","depth":2},{"value":"The Two Secrets You Provide: Read This First","id":"the-two-secrets-you-provide-read-this-first","depth":2},{"value":"How Onboarding Works","id":"how-onboarding-works","depth":2},{"value":"Documentation Map","id":"documentation-map","depth":2},{"value":"Getting Support","id":"getting-support","depth":2}],"frontmatter":{"id":"introduction","title":"Overview","seo":{"title":"Echo Webhooks"}},"lastModified":"2026-08-14T20:20:15.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/echosync-webhooks/introduction","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}