Skip to main content

Webhooks

Receive real-time notifications when events happen in your app. Signed with HMAC-SHA256.

Setup


Payload


Signature verification

The X-Webhook-Signature header contains a timestamp and HMAC:
Verify:

Events

Verification events

Pattern: verification.{channel}.{outcome} — channel is email or sms. Verification payloads include:
Expiration events add was_opened: true/false. Consent events add consent_decision and denial_reason. Delivery failures add error and channel.

Auth events

User events

System events


Managing endpoints


Delivery status


Limits

  • 10-second timeout per delivery
  • Max 10 retries with exponential backoff
  • Respond with 2xx within 5 seconds
  • 4xx = won’t retry. 5xx = will retry.