Lemon Squeezy ofrece webhooks HTTP salientes cubriendo el ciclo completo de pagos, suscripciones y licencias. La documentación registra los tipos de evento y proporciona ejemplos de payload, y existe una firma HMAC-SHA256 con un secret configurable. Estas son las piezas mínimas que un desarrollador necesita para arrancar.
Las brechas principales están en seguridad y fiabilidad: la protección ante replays no está documentada (sin ventana de tolerancia de timestamp), la rotación de secretos en caliente no aparece en docs, y el comportamiento de reintentos se describe solo de forma vaga. No hay destinos no-HTTP (solo webhooks HTTP), limitando la integración con arquitecturas cloud basadas en colas.
La observabilidad de entregas y gestión del dashboard son Not Assessed al requerir cuenta activa. Cuatro recomendaciones de esfuerzo docs o S pueden mover la nota de D a C/B.
| Criterio | Score | Estado |
|---|---|---|
|
Findability of webhook docs
Discovery & signup
|
2 | Scored |
|
In-product discoverability
Discovery & signup
|
N/E | Not Assessed |
|
Guided path to first webhook
Onboarding & first event
|
1 | Scored |
|
Test event / trigger
Onboarding & first event
|
N/E | Not Assessed |
|
Processing & handler guidance
Implementation guidance
|
0 | Not Supported |
|
Best-practices coverage
Implementation guidance
|
0 | Not Supported |
|
Machine-readable spec
Event catalog & schema
|
0 | Not Supported |
|
Signature scheme (webhooks)
Security & authentication
|
1 | Scored |
|
Replay protection (webhooks)
Security & authentication
|
0 | Not Supported |
|
Secret rotation
Security & authentication
|
0 | Not Supported |
|
Destination-native auth
Security & authentication
|
N/A | Not Applicable |
|
Destination type breadth
Delivery semantics & reliability
|
0 | Not Supported |
|
Retry policy
Delivery semantics & reliability
|
1 | Scored |
|
Delivery guarantee stated
Delivery semantics & reliability
|
0 | Not Supported |
|
API configuration
Setup surfaces
|
2 | Scored |
|
CLI support
Setup surfaces
|
0 | Not Supported |
|
Self-serve endpoint management
Consumer self-serve
|
2 | Scored |
|
Subscription granularity
Consumer self-serve
|
2 | Scored |
|
Local receiving story
Local dev & local-to-prod
|
1 | Scored |
|
Local-to-production transition
Local dev & local-to-prod
|
0 | Not Supported |
|
Discoverable index (llms.txt)
Agent / AI readiness
|
0 | Not Supported |
|
API access for agents
Agent / AI readiness
|
2 | Scored |