JavaScript SDK - Webhooks#

Outbound HTTP notifications with HMAC-signed deliveries.

Create and manage#

const { data: hook } = await db.webhooks.create({
  name: 'order.created',
  url: 'https://myapp.com/hooks/orders',
  events: ['order.created'],
  secret: 'signing-secret', // used to HMAC-sign deliveries
});

const { data: hooks } = await db.webhooks.list();
await db.webhooks.update(hook.id, { enabled: false });
await db.webhooks.remove(hook.id);
TypeScript

Deliveries#

const { data: deliveries } = await db.webhooks.listDeliveries(hook.id);
await db.webhooks.send(hook.id);                    // test delivery
await db.webhooks.retryDelivery(hook.id, deliveryId);
TypeScript

Verifying deliveries on your server#

Every delivery includes an X-Afribase-Signature header in the form sha256=<hex> (HMAC-SHA256 of the body with the webhook's secret), plus X-Afribase-Event and X-Afribase-Delivery headers.

import { createHmac, timingSafeEqual } from 'node:crypto';

function verifyWebhook(rawBody: string, signatureHeader: string, secret: string): boolean {
  const expected = createHmac('sha256', secret).update(rawBody).digest('hex');
  const a = Buffer.from(signatureHeader.replace(/^sha256=/, ''), 'hex');
  const b = Buffer.from(expected, 'hex');
  return a.length === b.length && timingSafeEqual(a, b);
}
TypeScript

Next: Edge functions.