Changelog

Latest updates and improvements.

Newv2.10.025.09.2026

The app in your language, and seven ready-made workflows

The app speaks your language

The whole app now follows the language you use in the Shopify admin. Available in English, German, French, Spanish, Italian, Dutch, Danish, Portuguese (Brazil and Portugal), Japanese, and Chinese (Simplified and Traditional). Change your admin language and the app follows on the next page load.

  • Every page, dialog and message is translated, including the webhook editor, the signature tester and its step-by-step diagnostics, History and the Help page.
  • The workflow templates show their title, description and setup note in your language in Shopify Flow.
  • Dates and numbers are shown the way your language writes them.
  • This help center is translated too. Every guide is available in the same languages; pick yours from the language menu.
  • Trigger and action names stay in English. Shopify Flow shows step names in English, so the app does too - the name you see in the app is always the one you find in Flow. Payload field names such as fieldOne do not change either.

Seven ready-made workflows in Shopify Flow

Open Flow, choose Browse templates and search for "webhook". Each template is a complete workflow on the Webhook Trigger; you only create the webhook and point your system at it.

  • Tag order when webhook received - a 3PL, ERP or no-code tool marks orders as shipped, invoiced or reviewed.
  • Add order note when webhook received - append a message from a support tool or ERP to the order note.
  • Mark order as paid when webhook received - your bank, invoicing or payment system confirms a payment.
  • Tag product when webhook received - a supplier, PIM or ERP keeps collections and badges in sync.
  • Create customer when webhook received - collect leads from landing pages and forms.
  • Update customer metafield when webhook received - a loyalty, CRM or points system stores a number on the customer.
  • Return order status when webhook received - answer a chatbot, help desk or customer portal with the payment and fulfillment status of an order, using the synchronous response.

Each template's setup note tells you which fields to map. See Workflow templates.

The new Shopify admin design

Shopify is rolling out a new look for the admin. In a store that has it, Workflow Webhooks now uses the same colors, typography and icons, so the app looks like the rest of your admin. In a store that does not have it yet, nothing changes.

Newv2.9.018.09.2026

Scheduled webhooks, 22 signature presets, form and XML bodies - on a faster interface

Your webhooks can now run on a timer, verify almost any sender's signature, and accept more than JSON.

Run a workflow on a timer from any API

A new Schedule tab on every webhook, and a direct way in: choose Create webhook and answer "What will call this webhook?" with Nothing - run it on a schedule. The app fetches a URL every 5 minutes up to once a day and sends the response into the webhook, so a Shopify Flow workflow can run on a schedule from any API.

  • Fire on every fetch, or only when the response changed.
  • Add request headers if the API needs them. They are stored encrypted.
  • Run now fetches once and shows you the response.
  • The tab shows how the schedule adds up against your plan. Runs appear in History as Scheduled.
  • A schedule that fails 20 times in a row pauses itself.

See Scheduled URL polling.

Signature verification for almost any sender

22 built-in presets, up from 6, each checked against the sender's own documentation: Stripe, GitHub, Shopify, Slack, Typeform, Calendly, Standard Webhooks (OpenAI, Supabase), Svix (Clerk, Resend), Paddle, Linear, WooCommerce, Square, Sentry, Vercel, Zendesk, Lemon Squeezy, Razorpay, Paystack, Customer.io, Sendcloud, Mollie and Sanity.

  • A sender without a preset is covered by a Custom signature: choose the header, the algorithm, the encoding, a timestamp with replay protection and the exact text that is signed.
  • A signature tester in the editor shows which verification step fails, and can generate a valid example request.
  • Creating a webhook now starts by asking what will send to it.

See Verifying signed webhooks, with a step-by-step guide for each sender.

More ways to authenticate

  • A static token can now arrive as a Bearer token, as Basic auth (username and password) or as a URL parameter, for senders that cannot set a custom header. A token in the URL is masked in History and never passed to Flow.
  • Rotate a secret without downtime. A second secret is accepted alongside the first, for static tokens and every signature scheme.
  • IP allowlist. Limit who can call the URL to the addresses or ranges you list, on top of any authentication. See IP allowlists.

See Authentication.

Form and XML bodies, and splitting arrays

  • Form posts, file-upload forms and XML are now read into mappable fields just like JSON. A body that is valid JSON is still read as JSON, so no existing sender changes behaviour.
  • Split arrays into runs. Point the new setting at a list in the payload and every item starts its own Flow run, up to 100 per request. Each item counts as one invocation.

See Body formats and splitting arrays.

A faster app, rebuilt on Shopify's web components

The whole app now runs on the web components of the Shopify admin itself instead of a separate interface library. There is less to load, so pages open faster, and every field, menu and dialog looks and behaves like the rest of your admin.

  • The webhook editor is a builder. Settings on the left; on the right the Endpoint card with the webhook URL and webhook ID, above Live Preview, Test and Usage - so you change a setting and watch a request arrive side by side.
  • The webhook list shows each webhook with its invocation count, how callers authenticate and when it last changed, with a menu per row to edit, enable, disable or delete.
  • Connecting a signed sender. A webhook for Stripe, GitHub or another provider shows the steps to connect it and a button to its setup guide, instead of a sample request that could never verify.

Also in this release

  • Blocked requests on the dashboard. Requests rejected by your plan limit used to leave no trace. The dashboard now shows how many were blocked in the last 30 days, and the plan card is a usage meter.
  • Pagination on the webhook list works, and Clear all in History also clears the Replayed filter.
  • Every page links to its guide in the help center, and the Help page lists our other apps for Shopify Flow.
  • Routine security maintenance. No action needed.
Newv2.8.002.09.2026

Return data from your Flow workflow to the caller

Until now a webhook could only acknowledge a request - your Shopify Flow workflow ran afterwards, and the caller never heard the outcome. Synchronous response changes that: the app holds the request open until your workflow sends data back, and returns it to the caller.

Useful whenever the caller needs an answer rather than a receipt - a form that shows a result, a system waiting on a computed value, a lookup.

How it works

Switch on Synchronous response under Advanced Settings on the webhook. Then build the workflow on the new Sync Webhook Trigger, and finish it with the new Return Webhook Response action.

Write the response body straight into the action using the trigger's variables:

{"ok": true, "orderId": "{{fieldOne}}", "email": "{{fieldTwo}}"}

or build something more involved in a Run Code action and bind the result.

Typical round trip is two to four seconds. If your workflow does not answer within 15 seconds the caller simply gets the normal response instead - never an error, and never a hang.

Full guide: Synchronous response

Nothing changes unless you switch it on

Off by default on every webhook. Existing webhooks keep answering immediately and keep using the standard Webhook Trigger, exactly as before.

Improvedv2.7.021.08.2026

A dedicated address for the API, and a lot more documentation

The REST API and MCP server now have a permanent home of their own:

https://shopify.workflow-webhooks.app

So the API is at https://shopify.workflow-webhooks.app/api/v1 and the MCP server at https://shopify.workflow-webhooks.app/api/mcp. Both are shown with a copy button on the Developer page.

Previously these lived on the app's embedded URL. Splitting them out means the address you paste into a script, a CI job or an AI assistant is stable and unrelated to how the app is embedded in your admin. The new hostname serves the API only - the app itself stays where it was, and nothing you have already set up needs changing.

Much more documentation

Nine new pages are live at docs.workflow-webhooks.app:

  • Create your first webhook - end to end, including wiring up the Shopify Flow side
  • Authentication - static token, HMAC, and presets for Stripe, GitHub, Shopify, Slack, Typeform and Calendly
  • Payload mapping and Flow variables - dot paths, nested values, and what to do when four fields are not enough
  • Duplicate delivery protection
  • History and troubleshooting - every rejection code and what to do about it
  • Calling a webhook from Flow
  • Plans and usage - what counts toward your limit and what does not
  • Sidekick and AI assistants
  • Frequently asked questions

The Developer API and MCP guide is published too.

Newv2.6.021.08.2026

Stop duplicate events running your Flow twice

Most systems retry a webhook if they don't get a quick reply. If the first attempt actually arrived, your Shopify Flow workflow runs twice for the same event - a second email, a second tag, a duplicate order note.

Duplicate delivery protection fixes that. If your sending system includes a unique id per event, tell us which header carries it and we ignore the repeats.

Set it under Advanced Settings -> Duplicate delivery on any webhook. Type the header name your sender uses - commonly Event-Id, Idempotency-Key or X-Request-Id.

  • The first request with a given id runs normally.
  • Any repeat within 24 hours gets a normal 200 OK response, so the sender stops retrying - but it is not sent to Flow again.
  • Suppressed duplicates don't count toward your plan limit.
  • You can still see them: the Live Request Inspector shows the request and labels it as a suppressed duplicate, so it never looks like the call vanished.

Leave the field empty and nothing changes - every request is processed, exactly as before. This is off by default on all existing webhooks.

Newv2.5.012.08.2026

Developer API and MCP server

Manage your webhooks from your own code, or from an AI assistant like Claude or Cursor.

  • New Developer page: create scoped API keys and get copy-ready connect commands for Claude Code, Claude Desktop, Cursor, VS Code, Gemini CLI and OpenAI Codex.
  • REST API at /api/v1 - list and manage webhooks, read invocation history and stats, list templates.
  • MCP server at /api/mcp, so an AI assistant can do the same in conversation.
  • Three access levels. Read keys can only look. Write keys can also create, update and delete webhooks. Execute keys can additionally fire a test invocation or replay a past one - which really does run your Shopify Flow workflows.
  • Your data stays protected. A webhook's auth token is never readable back through the API, and personal data in request payloads (email addresses, phone numbers, names, card numbers) is masked before it leaves the server.
Newv2.4.008.08.2026

Now called Workflow Webhooks - new docs, help center and in-app chat

Flow Webhooks is now Workflow Webhooks. Same app, same install, same webhooks - new name, matching the rest of our Workflow range.

  • New documentation site at docs.workflow-webhooks.app, with the full n8n, Make and Zapier walkthroughs including video guides.
  • New Help Center - report a bug, request a feature, or contact us through a proper form that reaches us directly, with screenshots attached.
  • In-app chat - the chat bubble is now on every page of the app, and it politely gets out of the way when a dialog is open.
  • Setup guide on the dashboard, walking you from your first webhook through to a working Shopify Flow workflow. It remembers whether you collapsed it.
Fixedv2.3.028.06.2026

Security update

Routine security maintenance: dependency updates and hardening across the app. No action needed.

Newv2.2.019.06.2026

Failure alerts, signature presets and richer payloads

  • Email notifications - get warned as you approach your plan limit, when you hit it, and when your webhooks start failing more than usual. Add extra recipients beyond the store owner, each with their own unsubscribe link.
  • HMAC signature presets - match the signing scheme of common senders without hand-rolling the format.
  • Opt in to more request data - choose per webhook whether to pass request headers, query-string parameters and the raw request body through to Flow.
  • Search invocation history by payload content.
Newv2.1.030.05.2026

Ask Shopify Sidekick about your webhooks

Sidekick can now answer questions about this app directly. Ask things like "do I have a webhook for my contact form", "is my n8n webhook enabled", "how many times did it fire this week" or "why did my last invocation fail".

Read-only - Sidekick can look at your webhooks, their configuration and their invocation history, but cannot change anything.

Improvedv2.0.022.05.2026

New EU infrastructure - faster and more reliable

Workflow Webhooks now runs on a new European cloud platform. Nothing changes in how you use it, but underneath:

  • Webhook processing moved to a managed queue with dead-letter handling, so a call is never silently dropped.
  • Databases and caches are region-local in the EU, with encryption at rest.
  • Merchant secrets - your static tokens and HMAC keys - are now encrypted with a dedicated key management service, not just stored encrypted at the disk level.
  • Redundant instances across availability zones.

The result is lower latency on webhook reception and far better behaviour under load.

Newv1.10.026.04.2026

Configurable auth header, and deliveries that heal themselves

  • Custom static-token header - the token header no longer has to be X-Api-Key. Set your own name per webhook in Advanced Settings to match whatever the sending system already sends. Reserved and proxy-controlled header names are rejected for safety.
  • Automatic session refresh - access tokens are now refreshed in the background, so long-running stores no longer see deliveries fail after a token expires.
  • Smarter retries - failed deliveries retry with backoff, and permanent failures stop retrying immediately instead of burning through attempts.
Improvedv1.9.024.02.2026

Performance and security hardening

  • Added database indexes that speed up history and statistics queries on busy stores.
  • Added real-user performance monitoring so we catch slow pages in the admin.
  • Security pass across the app: dependency updates and removal of unsafe HTML rendering.
Improvedv1.8.007.01.2026

Rebuilt dashboard and unsaved-changes protection

  • Rebuilt the dashboard around metric cards, a date range picker and an invocations chart.
  • Unsaved changes are now protected. Editing a webhook shows Shopify's save bar, and switching tabs or hitting back with pending edits prompts you first instead of quietly discarding them.
Fixedv1.7.114.12.2025

Faster history for high-volume stores

Reindexed webhook history. Stores with large invocation volumes will notice the history page and dashboard loading considerably faster.

Newv1.7.005.12.2025

Replay any invocation, and templates to get started

  • Replay - open any past invocation and send it again with one click. This is the fastest way to wire up a Flow workflow: record events in Flow, then replay a real call instead of re-triggering the source system.
  • Webhook templates - preconfigured starting points for n8n, Make, Zapier, contact forms and custom integrations.
Fixedv1.6.123.10.2025

Authentication and proxy path fixes

  • Fixed an authentication edge case that could reject valid requests.
  • Fixed proxy path resolution so app proxy URLs route correctly.
  • Corrected a display error on the webhook list.
Newv1.6.004.09.2025

Call webhooks from Flow, plus dashboard statistics

  • Flow action - the reverse direction. A Shopify Flow workflow can now call a webhook as an action step, so Flow can push data out as well as be triggered by it.
  • Dashboard statistics - invocation totals, success rate and a chart over your selected date range.
  • Invocation source tracking - history now records whether a call came from Flow, a test, curl or an external system, and you can filter on it.
Improvedv1.5.025.08.2025

Nested JSON now survives the trip into Flow

Shopify Flow variables are flat strings, so nested objects and arrays used to arrive unusable.

Values that are objects or arrays are now detected automatically and passed to Flow as JSON strings, so nothing is silently lost on the way in.

Newv1.4.022.08.2025

Plans and usage

Introduced subscription plans with a monthly invocation allowance, and usage tracking on the dashboard so you can see where you stand against your limit.

Every plan includes all authentication methods, field mapping, CORS, history and replay - plans differ only in monthly volume.

Newv1.3.010.08.2025

App proxy URLs and date filtering in history

  • App proxy endpoint - each webhook can now also be reached through a Shopify app proxy URL, which avoids cross-origin problems for browser-based callers.
  • Date range filter on the history page, so you can narrow down to the day something went wrong instead of scrolling.
Newv1.2.015.07.2025

Send any payload shape with Allow Custom Request Body

Four mapped fields are not always enough. Turn on Allow Custom Request Body under a webhook's Security settings and the entire incoming payload is passed through to Shopify Flow, on top of the four named fields.

Useful when the sending system's payload shape is not yours to control.

Improvedv1.1.014.06.2025

Faster loads and clearer webhook status

  • Webhook configuration is now cached, so receiving a call does less work and responds faster.
  • Disabled webhooks are clearly badged in the list, so it is obvious at a glance why one is not firing.
  • Reworked the webhook detail page, plus a batch of smaller fixes.
Newv1.0.031.05.2025

Workflow Webhooks 1.0 - trigger Shopify Flow from anywhere

The first release. Shopify Flow only reacts to events inside Shopify - this removes that limit.

  • Webhook endpoints - every webhook gets its own secure URL that any external system can POST to.
  • Three authentication modes - None for testing, a static token in the X-Api-Key header, or HMAC SHA256 for tamper-proof signing.
  • Payload mapping - map up to four fields out of the incoming JSON and use them in Flow as {{fieldOne}} to {{fieldFour}}.
  • Invocation history - every call is logged with its headers, payload, status and timing.
  • CORS support - switch it on to accept calls straight from a browser or storefront form.
  • Webhook dashboard - create, enable, disable and bulk-manage every endpoint in one place, with a one-click token generator.