← All guidesAfter launch

Webhooks & API

Let your own tools react to what happens in the app, and send pushes from n8n, Zapier or Make. Events, signing, retries, and the API endpoints.

Updated September 18, 2026

Open Webhooks & API under Developer. Both halves are on the Pro and Agency plans, and they are independent: webhooks let StoreToNative tell your tools something happened, and API keys let your tools ask StoreToNative to do something.

Outbound webhooks

Per app, add an https:// endpoint your tool listens on and choose which events to receive. Leave the events empty to receive all of them, including ones added later. Up to five endpoints per app. The signing secret is shown when the endpoint is created and can be shown again later.

Send test queues a ping delivery straight away, so you can check the wiring in the delivery log.

Events

Event When it fires
install A device opened the app for the first time.
first_app_order A device’s first order attributed to the app. “First” is per device, so a reinstall looks new.
cart_abandoned A cart went idle long enough for cart recovery to consider it abandoned.
push_opened A shopper opened a notification.
campaign_sent A push campaign finished sending.
product_back_in_stock A watched product came back into stock. Needs the alerts add-on.
product_price_drop A watched product’s price dropped. Needs the alerts add-on.
ping You pressed Send test.

Verifying a delivery

Each request carries X-STN-Signature, X-STN-Timestamp, X-STN-Event, X-STN-Delivery and X-STN-Event-Version. The signature is an HMAC-SHA256, in hex, of <timestamp>.<raw body> using your signing secret. Verify it against the raw body bytes, not a re-serialised copy, and reject deliveries whose timestamp is more than five minutes off. The id in the body stays the same across retries, so you can ignore a duplicate.

Tool notes from the page: in n8n use a Webhook node with Raw Body on and compute the HMAC in a Crypto node with the secret in a credential; in Zapier use Catch Raw Hook and a Code step; in Make use a Custom webhook with request headers and a Run JavaScript step.

Retries and the delivery log

A delivery that does not get a 2xx is retried after 1 minute, 5 minutes, 30 minutes, 2 hours and 12 hours, then marked failed. A redirect counts as a failure. After ten consecutive failures the endpoint is switched off and the reason is shown on its card; fix the endpoint and switch it back on.

The delivery log per endpoint shows each event, when it was sent, and Delivered, Queued, Retrying (try N) or Failed after N tries, with the status code and error text.

API keys

Keys are workspace-wide. Give each one a Name and a Scope: all apps in the workspace, or one app. The key is shown once and stored hashed; Revoke stops it immediately. Up to five live keys.

Keys work only on the /v1/api/ routes below. They cannot touch billing, the account or anything else in the console.

Endpoint What it does
GET https://api.storetonative.com/v1/api/whoami Confirms the key works and shows its scope.
GET https://api.storetonative.com/v1/api/apps/{appId}/audience How many devices a send would reach right now.
POST https://api.storetonative.com/v1/api/apps/{appId}/push Sends a push. Body: { "title": "…", "body": "…" }, title up to 80 characters and body up to 240.

Send the key as Authorization: Bearer <key>. Sends through the API are limited to 60 per hour per workspace, and they respect the Push add-on switch and each shopper’s notification preference.

curl -X POST https://api.storetonative.com/v1/api/apps/APP_ID/push \
  -H "Authorization: Bearer YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"title":"Weekend sale","body":"20% off everything until Sunday"}'

Still stuck? Open a ticket from Support in the console, or contact us.