REST API - Webhooks#

Outbound HTTP notifications with HMAC-signed deliveries.

EndpointMethodDescription
/projects/{id}/webhooksGETList webhooks
/projects/{id}/webhooksPOSTCreate a webhook
/projects/{id}/webhooks/{webhookID}PATCHUpdate a webhook
/projects/{id}/webhooks/{webhookID}DELETEDelete a webhook
/projects/{id}/webhooks/{webhookID}/deliveriesGETList deliveries
/projects/{id}/webhooks/{webhookID}/sendPOSTSend a test delivery
/projects/{id}/webhooks/{webhookID}/deliveries/{deliveryID}/retryPOSTRetry a delivery

Create:

{
  "name": "order.created",
  "url": "https://myapp.com/hooks/orders",
  "events": ["order.created"],
  "secret": "signing-secret"
}
JSON

Delivery headers#

Every delivery includes:

HeaderValue
X-Afribase-EventThe event name
X-Afribase-DeliveryDelivery id
X-Afribase-Signaturesha256=<hex> HMAC of the body with the webhook secret

Verifying a delivery#

import { createHmac, timingSafeEqual } from 'node:crypto';

function verifyWebhook(rawBody: string, signatureHeader: string, secret: string): boolean {
  const expected = createHmac('sha256', secret).update(rawBody).digest('hex');
  const a = Buffer.from(signatureHeader.replace(/^sha256=/, ''), 'hex');
  const b = Buffer.from(expected, 'hex');
  return a.length === b.length && timingSafeEqual(a, b);
}
TypeScript

Security#

  • Accepts the project API key (or a project-user session)
  • Scoped keys: webhooks:read, webhooks:write