# Webhooks quickstart

URL: https://igregulator.io/docs/webhooks/quickstart/
Markdown: https://igregulator.io/docs/webhooks/quickstart.md

> Receive your first iGregulator webhook in two minutes with webhook.site, no server needed: create an endpoint, fire a test event, read the signed payload.

This is "get it working in two minutes" — no signature verification
yet, no production-grade receiver. Point Ctrl+F at
[/docs/webhooks](https://igregulator.io/docs/webhooks/) when you're ready to harden.

## 1. Set up a receiver

Open [webhook.site](https://webhook.site). It hands you a unique
URL like `https://webhook.site/#!/<random-uuid>`. Copy the URL —
that's your temporary endpoint. Leave the page open; deliveries
show up in real time.

## 2. Create the webhook

1. Sign in to the
   [iGregulator dashboard](https://app.igregulator.io/webhooks).
2. Click **+ create webhook**.
3. Paste the webhook.site URL.
4. Subscribe to any event type for now — `license.status_changed`
   is the most common; you can change later.
5. Submit. You'll see a reveal dialog with a
   `whsec_<base64url>` secret — **copy it** (you'll need it when
   you harden later) and click "copy + close".

## 3. Fire a test delivery

Back in the dashboard, click **test** on your new endpoint row.
A result dialog pops up showing:

- `delivered: true`
- HTTP status your endpoint returned
- Latency in ms
- Response body

Switch to the webhook.site tab: the request is there, complete
with headers, including:

```
X-iGregulator-Event: test.ping
X-iGregulator-Event-Id: evt_...
X-iGregulator-Delivery-Id: test_evt_...
X-iGregulator-Signature: t=...,v1=...
```

That's a real production-shape delivery — just flagged
`livemode: false` in the envelope so you don't treat it as
business data.

## 4. Harden for production

- **Verify signatures.** See
  [/docs/webhooks § signature verification](https://igregulator.io/docs/webhooks/#4-signature-verification) —
  includes Node / Python / curl examples.
- **Replace webhook.site.** Stand up a real HTTP server; the same
  envelope + headers will land there.
- **Dedupe on `event_id`.** At-least-once delivery means duplicates
  during retries. See [Pattern C](https://igregulator.io/docs/webhooks/#7-integration-patterns).
- **Understand retries.** 7 attempts, jittered backoff — start at
  30 s, end at ~24 h. Details in
  [§5 retry policy](https://igregulator.io/docs/webhooks/#5-retry-policy).

Main reference: [/docs/webhooks](https://igregulator.io/docs/webhooks/).
