Skip to content

For developers · checked against the product 6 Oct 2026

A signed, versioned events API for custom-built stores.

Dvaarik's Custom Commerce Events API lets a store that is not on Shopify or WooCommerce tell the AI agent what happened: a checkout left open, a cash-on-delivery order waiting for confirmation, a cancellation or a failed delivery. Each event is an HTTPS POST signed with HMAC-SHA256 and pinned to API version 2026-08-30. The agent then contacts the customer the way the business chose, on WhatsApp or by phone, and records the answer.

Free signup, no card. The connection URL and signing key are created in your dashboard.

One event: a cash-on-delivery order to confirm

POST <connection URL from your dashboard>
Content-Type: application/json
X-Webhook-Api-Version: 2026-08-30
X-Webhook-Topic: order/cod_pending
X-Webhook-Event-Id: 2a1f0d7e-1c4b-4b6e-9f5a-3f2b1c0d9e8a
X-Webhook-Timestamp: 1791300000
X-Webhook-Signature: sha256=<hex>

{"order_id":"ORD-1042","order_number":"#1042",
 "customer_phone":"+919876543210","amount":"2499.00",
 "currency":"INR","item_count":2}

Which events can a custom store send to Dvaarik?

Dvaarik's Custom Commerce Events API accepts six topics: three for checkouts, two for cash-on-delivery orders and one for failed deliveries. Your store reports what happened; the business's own settings decide what the agent does next.

Custom Commerce Events API topics, version 2026-08-30
TopicSend it whenWhat Dvaarik does
checkout/updatedA shopper's checkout is still open and something changed: items, amount, phone or their permission to be messaged.Opens or refreshes one cart case. If cart recovery is on, a reminder goes out after the delay you chose, only to the audience you allowed.
checkout/completedThe checkout became an order.Stops every reminder for that checkout.
checkout/cancelledThe checkout was closed for good.Stops every reminder for that checkout.
order/cod_pendingA cash-on-delivery order was placed and nobody has confirmed the customer still wants it.Asks the customer to confirm or cancel, on WhatsApp or by phone as you configured, and records the decision.
order/cancelledThe order stopped being live, for any reason.Stops any follow-up already running for that order.
shipment/ndrA delivery attempt failed. Send the tracking number (AWB) and which attempt it was.Asks the customer whether to try delivery again or send the parcel back, and records the answer.

In short, a custom store sends Dvaarik facts, never instructions: there is no “send a WhatsApp now” event. Each topic reads a short list of fields, such as the order id, the customer's phone, the amount and the item count, and ignores everything else. Checkout events also carry a rising revision number and the customer's own link back to your checkout.

How are custom store events signed?

Every Custom Commerce Events API request carries five headers: the API version, the topic, a UUID event id, a Unix timestamp and an HMAC-SHA256 signature made with your business's private signing key.

  • Sign the raw bytes you send, not a re-serialised copy. A different key order or number format changes the signature.
  • The timestamp is inside the signature. A request more than five minutes from Dvaarik's clock, either way, is refused.
  • The business is identified by the key you signed with. An id in the body is ignored.
  • Partner clients receive a connection URL on their partner's own verified domain.

The signature

signed_payload = timestamp + "." + raw_request_body
signature      = "sha256=" + hex(HMAC_SHA256(signing_key, signed_payload))

The header names start with X-Webhook-: Api-Version, Topic, Event-Id, Timestamp and Signature. Requests are limited to 64 KB each and 600 a minute for one business.

How does the custom store API handle retries and duplicates?

Your store sends a new lower-case UUID for each genuine event and repeats the same one on every retry, so Dvaarik stores each event once. Duplicates are also collapsed on the order id, or on the tracking number and attempt for a failed delivery, so the customer is not asked twice.

Custom Commerce Events API responses
ResponseMeaning and what to do
202Stored durably. The event is Dvaarik's now; nothing else to do.
400Malformed: unsupported version or topic, bad event id or a timestamp outside the window. Fix the request; do not retry it.
401The signature did not verify. Check the key and that you signed the exact bytes you sent.
409That event id was already used for a different event. Use a new UUID for each genuine event.
429Too many deliveries this minute. Back off and retry.
503The event could not be stored. Retry with the same event id.

The custom store API asks you to retry only on 503, 429 or a timeout. A 202 means the event is stored, not that the customer has been contacted: the business's workflow, calling hours, the customer's permission and Do Not Contact decide that.

What happens after your store sends an event?

Dvaarik turns each event into one case on the business's COD confirmations, Failed deliveries or Cart recovery page, and the owner's settings decide whether the agent messages, calls or leaves it for the team.

  1. 01The owner picks the contact strategy for each workflow: WhatsApp then a call, a call first, WhatsApp only, or manual review.
  2. 02The agent waits for the delay the owner chose. Customers who opted out of the business's WhatsApp messages are not messaged, and calls wait for calling hours and skip the Do Not Contact list.
  3. 03Cart reminders go only to shoppers who agreed to messages, unless the owner chooses everyone who left a number. Calls go only to customers whose consent to be called is recorded.
  4. 04The customer answers with a WhatsApp button, in chat or on the call, and the decision is saved on the case for the team.

What else can a custom store connect?

Besides events, a custom store can let the Dvaarik agent search its live catalogue and answer with product photos and links, while every message goes out from the business's own WhatsApp number.

Live product search from your own software

Point the agent at a search URL your inventory software already exposes. It searches live when a customer asks, with no catalogue sync, and only the catalogue fields you select reach the AI.

Product photos and links in answers

When your feed includes a product's image and page address, the agent's answers in chat can show the photo with a link to that product on your own site.

Your own WhatsApp number

Confirmation, failed-delivery and cart messages go out from your own WhatsApp Business number. Meta bills its message charges to that account, and Dvaarik adds no markup.

How do I get the full custom store API guide?

The Dvaarik dashboard gives your developer everything needed to connect: on the COD confirmations, Failed deliveries or Cart recovery page, open the follow-up settings and choose Connect my own checkout or delivery software.

  1. 1.Create your connection to get the connection URL and a private signing key.
  2. 2.Copy or download the setup guide for your developer: version, signing steps, supported events and an example event.
  3. 3.Send a signed test event and check that it appears in the right queue.
  4. 4.Choose the contact method, waiting time and expiry, then switch the workflow on.

Prefer to read the contract before signing up? Ask us for the API guide and we will send it to your developer.

What does the custom store API not do yet?

Dvaarik's custom store connection receives events today; acting on your store's own API is still being added.

  • Writing a decision back into your store. A confirmed, cancelled or re-addressed order is recorded in Dvaarik for your team to apply; Dvaarik does not yet call your store's API to change the order.
  • Placing orders directly into your own order system. A versioned order API (create, status and cancel) exists, but it is switched on only for individual stores in a controlled rollout. Ask us before you build against it.
  • Live delivery-status lookup from your own API. The connection can be saved and tested, but status sync is not switched on yet.
  • Prepaid order or shipment-status events. The API carries checkout, cash-on-delivery, cancellation and failed-delivery events only.
  • A public documentation site. The full guide comes from your dashboard or from us on request.

Custom store API questions

Dvaarik's Custom Commerce Events API is described below as the product works on 6 Oct 2026. Prices in force from 5 October 2026.

No. Any store that can send an HTTPS POST when a checkout changes, a cash-on-delivery order is placed, an order is cancelled or a delivery fails can use Dvaarik's Custom Commerce Events API. Shopify stores can connect directly instead, and WooCommerce stores can use this API for cart events.

Each request is signed with HMAC-SHA256 over the timestamp, a dot and the raw request body, using the private signing key your dashboard creates for your business. Dvaarik rejects a timestamp more than five minutes from its own clock in either direction, and the business is identified by the key, never by anything in the body. Requests also carry the API version, 2026-08-30, the topic and a unique event id.

Send the same event id on every retry and Dvaarik stores the event once. As a second safeguard, duplicates are also collapsed on the order id, or on the tracking number and attempt for a failed delivery, so a queue that retries with a fresh id still does not ask the customer twice. Reusing one event id for a different event returns 409.

No. A 202 means Dvaarik has stored the event durably. Whether and when the customer is contacted depends on the workflow the business has switched on: the contact method, the waiting time, calling hours, the customer's permission and Do Not Contact.

Inside the dashboard. On the COD confirmations, Failed deliveries or Cart recovery page, open the follow-up settings and use Connect my own checkout or delivery software. It creates your connection URL and private signing key and gives your developer a guide to copy or download, with the version, signing steps, supported events and an example. You can also write to hello@dvaarik.com for the full guide; there is no public documentation site yet.

Not yet. The customer's decision is recorded on the case for your team to apply. A separate, versioned order API for creating, checking and cancelling orders in your own system is switched on only for individual stores in a controlled rollout, so ask before building against it.

Nothing per event. Dvaarik's usual usage prices apply when the agent works: ₹0.05 per successful AI reply and ₹0.50 a call minute in 30-second steps, with no monthly fee. WhatsApp template messages are billed by Meta to your own WhatsApp Business account.

Your store reports it. The agent follows up.

Sign up as a D2C brand, create your connection, send a test event and watch it land in the right queue before you switch anything on.