notification.updated
Event
POST <your callback URL>
A notification was delivered on one of its channels, or every channel failed (attempts says what happened on each).
Verify every callback
Check X-PaalChat-Signature on the raw body, reject timestamps older than 5 minutes, and de-duplicate on X-PaalChat-Delivery. Answer 2xx within 10 seconds. See Webhooks and callbacks.
Headers
X-PaalChat-Event
string
X-PaalChat-Delivery
string
Unique per event (equals body id). De-duplicate on it.
Format uuid.
X-PaalChat-Signature
string
t=<unix seconds>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Reject if invalid or older than 300 seconds.
Pattern ^t=\d+,v1=[a-f0-9]{64}$.
Body
id
string
Equals X-PaalChat-Delivery.
Format uuid.
sandbox
boolean
true for sandbox businesses (test keys) - nothing reached WhatsApp.
event
any
Always notification.updated.
occurred_at
string
Format date-time.
business
object
external_id
string
business.external_id
data
object
notification_id
integer
data.notification_id
reference
string | null
data.reference
status
string
data.status
One of: delivered, failed.
channel
string | null
data.channel
attempts
array of objects
data.attempts