Python SDK - Webhooks#

Outbound HTTP notifications with HMAC-signed deliveries.

Create and manage#

hook = db.webhooks.create(
    name="order.created",
    url="https://myapp.com/hooks/orders",
    events=["order.created"],
    secret="signing-secret",  # used to HMAC-sign deliveries
)

db.webhooks.list()
db.webhooks.update(hook_id, enabled=False)
db.webhooks.remove(hook_id)
Python

Deliveries#

db.webhooks.list_deliveries(hook_id)
db.webhooks.send(hook_id)                       # test delivery
db.webhooks.retry_delivery(hook_id, delivery_id)
Python

Verifying deliveries on your server#

Every delivery includes an X-Afribase-Signature header in the form sha256=<hex> (HMAC-SHA256 of the body with the webhook's secret), plus X-Afribase-Event and X-Afribase-Delivery headers.

import hashlib
import hmac

def verify_webhook(raw_body: bytes, signature_header: str, secret: str) -> bool:
    expected = hmac.new(secret.encode(), raw_body, hashlib.sha256).hexdigest()
    received = signature_header.removeprefix("sha256=")
    return hmac.compare_digest(expected, received)
Python

Next: Edge functions.