Browse documentation

A webhook never arrives

Tell apart a request that never reached MsgOrb from one that arrived and was refused.

Open Notifications and look at the ingest feed for the event type you are sending. What you see there splits the problem in two, and the two halves have completely different causes.

The request is not in the feed at all

Nothing was rejected, because nothing arrived. Three causes, in the order they actually occur.

The apex domain. msgorb.com redirects to www.msgorb.com. A browser follows that silently, which is why the address works when you paste it into one. Most integration platforms do not: they follow the redirect without resending the request body, or abandon it. Your webhook URL must begin https://www.msgorb.com. Copy it from the Notifications page rather than typing it from memory.

This failure is invisible from both sides. Your platform reports the request as sent. MsgOrb has no record of it, because the request never reached the code that keeps records.

No `x-api-key` header. A request without a valid key is refused before anything is written, so it leaves no trace either. Check the header name is exactly x-api-key and the value matches the key on the Notifications page.

The wrong method. The endpoint accepts POST only.

The request is in the feed with a status

MsgOrb received it and answered. Match the status code:

202 accepted and queued. If no message arrived, the problem is delivery rather than ingestion: see Nothing is being delivered.

400 a required field is missing, or recipient_phone is not a valid international number. The response names what was wrong.

401 the API key is not recognised.

403 the recipient replied STOP. WhatsApp policy forbids messaging them until they opt back in.

409 no approved template is configured for that event type.

422 the type or business parameter does not match anything in your workspace.

Prove an integration without sending anything

Add &dry_run=1 to your webhook URL. MsgOrb checks the key, the saved field mapping, the required fields, the phone number and the opt-out status, then reports exactly what it found and sends nothing. It is the fastest way to validate an integration before it goes anywhere near a customer.