Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

COUNT’s “Expanded webhook events” update added bill and invoice lifecycle notifications to its Partner API. The expansion, dated May 10, 2026, covers creation, updates, and deletion; integrations can subscribe to each event type separately.

Which webhook events did COUNT add?

The COUNT Partner API’s current event list includes six bill and invoice events:

  • invoice.created
  • invoice.updated
  • invoice.deleted
  • bill.created
  • bill.updated
  • bill.deleted

These join existing lifecycle events for customers, vendors, and transactions. COUNT’s changelog dates the expansion to May 10, 2026; the current event list is in the COUNT Webhooks API reference, last updated June 10, 2026. An accounting integration can use the notifications to react to record changes instead of repeatedly polling the API.

How subscriptions work

Each subscription is for one event type. A workspace permits one subscription per event type per partner, so creating a duplicate returns an error; update the existing subscription instead. Only subscriptions with status active receive deliveries. Paused and disabled subscriptions do not.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Manage subscriptions through the /partners/webhooks collection or an individual /partners/webhooks/{uuid} resource. The documented methods are GET and POST on the collection, and PATCH and DELETE on an individual subscription. Deleting a subscription stops its deliveries immediately.

What a delivery requires

COUNT sends an HTTPS POST containing a JSON body with id, event, apiVersion, occurredAt, team, and data. The callback must be publicly reachable over HTTPS. Localhost and private IP addresses are rejected when a subscription is created or updated.

Verify signatures with the raw body

Signing is optional. If a subscription has a signing secret, COUNT includes an X-Webhook-Signature header in the form sha256=<hex>. The hexadecimal value is an HMAC-SHA256 digest of the raw request body, using the secret. Verify against the unmodified request bytes—not a parsed and re-serialized JSON object—because changing the bytes changes the digest.

The secret is write-only: list and retrieve responses do not return it. Save it securely when creating or updating the subscription so your receiver can validate subsequent requests.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Test a receiver before production

COUNT’s documentation suggests using a request-catcher service such as webhook.site during local development: point a subscription at it, trigger an event, and inspect the request payload and signature header. Treat that as a development check, not a production callback endpoint. For a working integration, use a publicly reachable HTTPS receiver and confirm it can handle the event type and, when configured, validate the signature.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.