Docs βΊ Webhooks
Legacy callback URL
Single signed callback per API key.
Before multi-endpoint webhooks existed, each API key could carry one callback URL. It still works, and existing integrations don't need to change. New integrations should use webhooks.
How it works
- Dragonfly sets the key's
callbackUrlduring onboarding: ask support, or provide it in your access request. - On every status change of an order created with that key, Dragonfly POSTs a signed JSON event:
order.created,order.driver_assigned,order.picked_up,order.delivered,order.cancelledand others. X-Dragonfly-Signatureis the hex HMAC-SHA256 of the raw body, keyed with your API key's signing secret (the same secret used for HMAC requests).
javascript
const expected = crypto.createHmac('sha256', process.env.DRAGONFLY_SIGNING_SECRET).update(rawBody).digest('hex')
const ok = crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(req.headers['x-dragonfly-signature'] ?? ''))Webhooks vs. callback URL
Webhooks (/v1/webhooks) | Callback URL | |
|---|---|---|
| Endpoints | Many per key, self-managed | One per key, set by Dragonfly |
| Event filter | Yes | No |
| Retries & log | Yes | Best effort |
| Payload | Full delivery (driver, POD, ETA) | Order summary |
Something unclear or missing? Tell us.