Docs / Reference
Zapier, Make and n8n
Connect OrderDen to Zapier, Make or n8n with a webhook and an API key, and where each comes from.
Zapier, Make and n8n all watch for something happening in one app and do something about it in another, without you writing a program. OrderDen works with all three, and with anything else that can receive a webhook and call a REST API.
Which one to use depends on the rest of your tools:
| How OrderDen appears | Best when | |
|---|---|---|
| Zapier | Webhooks by Zapier and its API request action | You already pay for Zapier |
| Make | Webhook and HTTP modules | You want a visual scenario with branches and loops |
| n8n | Webhook and HTTP nodes | You host it yourself, or want to check the signature |
All three use the same two parts: webhooks tell the platform what happened, and the API lets it write back. Read those two pages once and the rest is setup.
Before you start
Both parts need credentials, made in Company Settings → API keys by an owner or admin:
- An API key (
od_live_and 40 hex characters, shown once) for anything the automation writes back into OrderDen. It has the permissions of whoever created it, so a key made by someone who can't record payments makes an automation that fails at that step. - A webhook endpoint, under Webhooks, pointed at the URL the platform gives you. It comes with a signing secret, also shown once, which proves a delivery came from OrderDen.
Neither is shown again. If you lose the key, revoke it and make another; if you lose the secret, rotate it, which stops the old one right away.
Treat them as passwords. Anything holding one, whether a scenario, a workflow or a screenshot in a support thread, holds the keys to your workspace.
A workspace can have up to 10 webhook endpoints.
Zapier
OrderDen's own Zapier app isn't published yet. Until it is, use Zapier's built-in tools:
- Start a Zap with Webhooks by Zapier → Catch Hook and copy its URL.
- Add that URL as a webhook endpoint in OrderDen and pick your events.
- Press Send test in OrderDen so Zapier sees a delivery. The test arrives as
a
client.createdevent with"test": trueinsidedata, so filter it out before any step that changes something. - Write back with Webhooks by Zapier → Custom Request (or API Request),
sending
Authorization: Bearer od_live_…and anIdempotency-Keyheader.
Checking the signature in Zapier needs Catch Raw Hook and a code step. Without that, treat the hook URL as a credential and keep it private.
Make
- Start a scenario with a Custom webhook module and copy its URL.
- Add that URL as a webhook endpoint in OrderDen, pick your events, and copy the signing secret.
- Put the module in Redetermine data structure and press Send test in
OrderDen. The test delivery's
datais a small made-up object, so Make learns the envelope (id,type,createdAt,data) rather than a real record; run a real event once to fill in the rest. The test flag is atdata.test. - Write back with HTTP → Make a request, sending
Authorization: Bearer od_live_…and anIdempotency-Keyheader.
Make parses the body before any formula sees it, so it can't check the OrderDen
signature. Treat the webhook URL as a credential and keep it private. To ignore
an event arriving twice, turn on Get request headers and key on
X-OrderDen-Event-Id.
n8n
n8n can check the signature:
- Start a workflow with a Webhook node, set the method to
POST, turn on Raw body, and copy its production URL (the test URL only listens while you're watching it). - Add that URL as a webhook endpoint in OrderDen, pick your events, and copy the signing secret.
- Check the signature in a Code node. The format is on Webhooks: an HMAC over the timestamp and the raw body. Raw body gives the node the bytes to hash.
- Write back with an HTTP Request node using a Header Auth credential
holding
Authorization: Bearer od_live_….
Activate the workflow when you're done. An inactive one answers 404, and when 25 deliveries in a row have failed every retry, the endpoint switches itself off.
Anything else
Nothing above is special to these three. Any tool that can be given an HTTPS URL and send a bearer token will work. The delivery format, the signature and the retries are on Webhooks, and every endpoint is in the API reference and the API explorer.
If the tool can't hold a public URL (a spreadsheet script, a till behind a shop
router), it can poll instead: most lists take ?updatedSince=<timestamp> and
return what's changed. See
Webhooks.
For an AI assistant, /llms.txt is a map of the API and the guides, and
/llms-full.txt has every endpoint and event in one file. The spec is at
/api/v1/openapi.json.
Everything on this page is on the free tier: one person, the whole product, no card.
Start free