test.ping
Manually triggered test event (POST /v1/webhooks/test). Signed and delivered like every real event. data.message says what it is; data.requested_at is when the test was requested.
When it fires
QuotaStack sends this when you ask for it, with the test call. The event goes down the same pipeline as a real one, signed the same way, with the same retries.
When it does not fire
QuotaStack never raises this on its own. Nothing a customer does can set it off. The payload carries no customer_id. This event is about your endpoint, not any one customer.
| Field | Type | Meaning |
|---|---|---|
messagerequired | string | |
requested_atrequired | string (date-time) |
{
"event_id": "0192f5a4-7c31-7b8e-9a2d-4f6c8e1b3a51",
"event_type": "test.ping",
"tenant_id": "0192f5a4-7c31-7b8e-9a2d-4f6c8e1b3a01",
"environment": "live",
"created_at": "2026-07-28T12:00:00Z",
"data": {
"message": "Test event from QuotaStack. Your endpoint and signature verification work.",
"requested_at": "2026-07-28T12:00:00Z"
}
} What to do
Check your signature code against it before you go live. Then read the webhook log to see what your endpoint sent back.
Which calls fire this
Delivery
QuotaStack guarantees at-least-once delivery. An event may be delivered more than once if your endpoint returns a non-2xx response, the connection fails, or the request exceeds the delivery timeout.
Delivery timeout: 5 seconds per attempt. If your endpoint does not return a 2xx within 5 seconds, the attempt is treated as a failure and retried. Not configurable today.
One webhook URL per tenant. Multiple URLs and per-event routing are not supported. Configure the URL via the tenant config endpoint.
Retry schedule
If delivery fails (non-2xx response, timeout, or network error), QuotaStack retries with exponential backoff:
| Attempt | Delay after previous |
|---|---|
| 1 | Immediate |
| 2 | 30 seconds |
| 3 | 5 minutes |
| 4 | 30 minutes |
| 5 | 2 hours |
| 6 | 8 hours |
| 7 | 24 hours |
After 7 failed attempts, the event is moved to a dead letter queue. Dead-lettered events are not lost — you can requeue them yourself, from the dashboard (Activity → Webhooks → Redeliver) or the API:
curl -X POST https://api.quotastack.io/v1/webhooks/events/{event_id}/redeliver \
-H "X-API-Key: $QS_KEY" \
-H "Idempotency-Key: redeliver:{event_id}"
Redelivery resets the event to pending with a fresh retry schedule (7
new attempts). The next attempt signs with your current secret —
useful when the event dead-lettered because of a secret rotation or an endpoint
outage you have since fixed. Only dead_letter events can be
redelivered; the call returns 409 for events in any other status.
Handling duplicates
Because delivery is at-least-once, your webhook handler should be idempotent. Use
the webhook-id header for deduplication — if you have already
processed an event with that ID, return 200 and skip processing.
Loading…