Docs β€Ί Webhooks

Legacy callback URL

Single signed callback per API key.

Before multi-endpoint webhooks existed, each API key could carry one callback URL. It still works, and existing integrations don't need to change. New integrations should use webhooks.

How it works

  • Dragonfly sets the key's callbackUrl during onboarding: ask support, or provide it in your access request.
  • On every status change of an order created with that key, Dragonfly POSTs a signed JSON event: order.created, order.driver_assigned, order.picked_up, order.delivered, order.cancelled and others.
  • X-Dragonfly-Signature is the hex HMAC-SHA256 of the raw body, keyed with your API key's signing secret (the same secret used for HMAC requests).
javascript
const expected = crypto.createHmac('sha256', process.env.DRAGONFLY_SIGNING_SECRET).update(rawBody).digest('hex')
const ok = crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(req.headers['x-dragonfly-signature'] ?? ''))

Webhooks vs. callback URL

Webhooks (/v1/webhooks)Callback URL
EndpointsMany per key, self-managedOne per key, set by Dragonfly
Event filterYesNo
Retries & logYesBest effort
PayloadFull delivery (driver, POD, ETA)Order summary

Something unclear or missing? Tell us.