Webhooks
FFL360 allows you to configure webhooks on the store level. You can find the secrets and other webhook details under Admin section inside FFL 360.
Configuring Webhooks
Requirements
You can set a public endpoint in the webhook section. You endpoint must meet the following requirements:
- It should support HTTP POST method.
- The webhook call must be completed within 20 seconds.
- It must return a HTTP response status 204 for success, any other status is considered as failure.
Payload
The payload of the webhook is in JSON format and an example is given below. Exact payload details depends on your product license.
{
"dealer": {
"preferredShippingAddress": {
"street": "595 Market St",
"city": "San Francisco",
"state": "CA",
"zipCode": "94105",
"preferredAddressType": "mailingAddress", //
"RBDI": "commercial" // This field is subject to license agreement
},
"contact": {
"name": "Jon Doe",
"email": "",
"primaryPhoneNumber": ""
},
"businessName": "CHATTAHOOCHEE MUNITIONS, LLC",
"CFD": "67252", // This field is subject to license agreement
"fflLicenseNumber": "1-58-121-07-8H-22932",
"abbreviatedFFLNumber": "1-58-22932",
"fflExpirationDate": "08/01/2028",
"EIN": "451554762", // This field is subject to license agreement
"FFLLicenseType": "07",
"SOTOperationType": "62",
"SOTClass":"Class 2",
"isNFA-SOTOnFile": true
},
"transfer": {
"transferId": 19338,
"orderId": "17330",
"source": "E-commerce",
"status": "ready",
"transferProof": "https://documents.masterffl.com/proofs/17330.pdf", // This field is subject to license agreement
"transferSellerPacket": "https://documents.masterffl.com/ffl-transfer-proofs/d808733f-e160-4a90-8478-66d966b67901/223009/7e3902b0-0fe1-4ffa-b9a8-33f05f8505d5/transfer_seller_packet_17330.pdf", // This field is subject to license agreement
"isDealerReassigned": false
}
}Authorization
To prevent and unauthorized invocations, FFL360 attaches signature to every webhook invocation. Clients should verify the signature and process the request only if signature is matched.
The signature is sent under header: x-signature
Clients can match the signature by recomputing the signature using HMAC algorithm. Please look at the sample code for your platform:
import crypto from "crypto";
const signatureHeader = req.headers["x-signature"]; //example: sha256=xxxxxxxxxxxxxxxxxxx
const computedSignature = crypto
.createHmac("sha256", secret)
.update(rawBody, "utf8")
.digest("hex");
const valid = crypto.timingSafeEqual(
Buffer.from(signatureHeader.split("=")[1]),
Buffer.from(computedSignature)
);
if (!valid) {
console.warn("Signature could not be matched");
return res.status(401).send("Signature mismatch");
}
//The signature is matched, you can process it!
//Finally return the success response
return res.status(204)
Backward Compatibility
Failover and Retries
After invoking the webhook, if FFL360 does not get a success response within 20 seconds, it is considered as a failed attempt. FFL360 will attempt to invoke the webhook 2 more times, and if these 2 subsequent attempts also fail, then the webhook is never called again for that transfer.
Furthermore, if we are not able to call webhook successfully for 5 transfers in a row, the webhooks are automatically disabled for security reasons. You can enable it back once you troubleshoot and resolve the issues.
Updated 4 months ago