PHP SDK - Webhooks#

Outbound HTTP notifications with HMAC-signed deliveries.

Create and manage#

$webhook = $db->webhooks->create(
    name: 'Order Created',
    url: 'https://myapp.com/hooks/orders',
    events: ['order.created'],
    secret: 'whsec_...', // used to HMAC-sign deliveries
);

$db->webhooks->list();
$db->webhooks->update($webhook->data['id'], enabled: false);
$db->webhooks->remove($webhook->data['id']);
PHP

Deliveries#

$db->webhooks->listDeliveries($webhookId);
$db->webhooks->send($webhookId);                            // test ping
$db->webhooks->retryDelivery($webhookId, $deliveryId);
PHP

Verifying deliveries on your server#

Every delivery includes an X-Afribase-Signature header in the form sha256=<hex> (HMAC-SHA256 of the body with the webhook's secret), plus X-Afribase-Event and X-Afribase-Delivery headers.

function verifyWebhook(string $rawBody, string $signatureHeader, string $secret): bool
{
    $expected = hash_hmac('sha256', $rawBody, $secret);
    $received = preg_replace('/^sha256=/', '', $signatureHeader);

    return hash_equals($expected, $received);
}
PHP

Next: Edge functions.