PHP SDK - Webhooks#
Outbound HTTP notifications with HMAC-signed deliveries.
Create and manage#
$webhook = $db->webhooks->create(
name: 'Order Created',
url: 'https://myapp.com/hooks/orders',
events: ['order.created'],
secret: 'whsec_...', // used to HMAC-sign deliveries
);
$db->webhooks->list();
$db->webhooks->update($webhook->data['id'], enabled: false);
$db->webhooks->remove($webhook->data['id']);
PHPDeliveries#
$db->webhooks->listDeliveries($webhookId);
$db->webhooks->send($webhookId); // test ping
$db->webhooks->retryDelivery($webhookId, $deliveryId);
PHPVerifying deliveries on your server#
Every delivery includes an X-Afribase-Signature header in the form
sha256=<hex> (HMAC-SHA256 of the body with the webhook's secret), plus
X-Afribase-Event and X-Afribase-Delivery headers.
function verifyWebhook(string $rawBody, string $signatureHeader, string $secret): bool
{
$expected = hash_hmac('sha256', $rawBody, $secret);
$received = preg_replace('/^sha256=/', '', $signatureHeader);
return hash_equals($expected, $received);
}
PHPNext: Edge functions.