{
"event": "service.suspended",
"data": {
"service_id": "c2a10f3e-8b7a-4d2e-9c1a-1a2b3c4d5e6f",
"application_id": "c2a10f3e-8b7a-4d2e-9c1a-1a2b3c4d5e6f",
"external_id": "store_88"
},
"sent_at": "1788265862201"
}Service suspended
service.suspended. The application was suspended: by you (the suspend endpoint or the console) or by Tawked. Sent to the partner webhook. Verify tawked-signature against the raw body before trusting it, and make handling idempotent: a delivery can arrive more than once, and deliveries are not guaranteed to arrive in order.
{
"event": "service.suspended",
"data": {
"service_id": "c2a10f3e-8b7a-4d2e-9c1a-1a2b3c4d5e6f",
"application_id": "c2a10f3e-8b7a-4d2e-9c1a-1a2b3c4d5e6f",
"external_id": "store_88"
},
"sent_at": "1788265862201"
}Authorizations
Authorization: Bearer . An application key (tk_live_, tk_test_) has full access, which covers every product and any product added later, or custom access, chosen when the key is created: one or more of the scopes verify:check, verify:send (includes verify:check), notifications:read, notifications:send (includes notifications:read). A call outside the key's access answers 403 insufficient_scope and names the scope it needs in the WWW-Authenticate response header. A partner key (tk_partner_) always has full access. Whatever its access, a key is a server-side secret.
Headers
Milliseconds since the epoch, as a string; the same value as sent_at.
Hex HMAC-SHA256 of "{timestamp}.{raw body}" with your webhook secret.
The event name, the same as event in the body.
service.suspended Response
Any 2xx answer within 5 seconds acknowledges the delivery. Anything else, a redirect or no answer in time is retried: 5 attempts in all, the first at once and the next after 1 min, 5 min, 30 min, 2 h.