Webhooks
Receive real-time notifications when events happen in your app. Signed with HMAC-SHA256.Setup
Payload
Signature verification
TheX-Webhook-Signature header contains a timestamp and HMAC:
Events
Verification events
Pattern:verification.{channel}.{outcome} — channel is email or sms.
Verification payloads include:
was_opened: true/false. Consent events add consent_decision and denial_reason. Delivery failures add error and channel.
Auth events
User events
System events
Managing endpoints
Delivery status
Limits
- 10-second timeout per delivery
- Max 10 retries with exponential backoff
- Respond with 2xx within 5 seconds
- 4xx = won’t retry. 5xx = will retry.