Neu Shop API webhook returning 403 during external script execution testing

deltaexector

Neues Mitglied
28. September 2026
1
0
Hi everyone, I have been running some automated workflow tests on our staging JTL-Shop 5 instance to check how external order state webhooks react under rapid status changes. While standard backend syncing runs without issues, our external staging client frequently drops connections and returns generic 403 forbidden responses during batch status updates.



We tried inspecting the request payloads from the sandbox environment, and it seems server-side security rules flag the request headers whenever our custom deltaexector script pushes rapid multi-threaded queries to the REST endpoint. The session cookies appear to invalidate mid-process, which leads to interrupted updates and temporary IP blocks on the staging server.



Has anyone experienced similar ModSecurity or Nginx rate-limiting conflicts when running automated testing scripts against JTL endpoints, and what would be the recommended way to whitelist these calls without lowering shop security?
 

Ähnliche Themen