Receiving webhooks.
Every event is a signed POST with a JSON body. Verify the signature on the raw body, deduplicate on the event ID, and reply with a 2xx.
What you get
Standard Webhooks
Headers webhook-id, webhook-timestamp and webhook-signature, an HMAC-SHA256 over the ID, timestamp and body.
Tenant and environment on every event
Each event carries its type, ID, time, environment and tenant.
At least once, unordered
Deduplicate on id. Message events carry a sequence number.
Secret rotation
During a rotation both secrets sign for 24 hours.
Safe destinations
Live endpoints must use HTTPS and resolve to a public address. Redirects are not followed.
Published egress ranges
At launchThe IP ranges webhooks come from, with notice before they change.
How it works
Add an endpoint
Register the URL, choose event types and tenants, and store the whsec_ secret.
Verify
Pass the raw body, headers and secret to verifyWebhook, or any Standard Webhooks library.
Deduplicate and respond
Ignore IDs you have seen and return a 2xx quickly.
Replay if needed
After fixing an endpoint, replay failed deliveries from the log.
Questions
How long are failed deliveries retried?
For about three days. Then the endpoint is disabled and its owners are emailed.
Do sandbox webhooks look different?
No. They use the same schema and signatures as Live.
Which events are there?
Message lifecycle, fallback, inbound replies, opt-in and opt-out, template status changes, sender restrictions and a test event.
Related
- WebhooksAvailableSigned events for delivery, replies, opt-outs, template changes and sender restrictions, retried for about three days and replayable.
- SDKAvailableA typed server-side SDK for Node with automatic idempotency keys, careful retries, typed errors and a webhook verifier.
- Error codesAvailableStable request error codes and delivery outcome codes, each with a cause, a fix, and whether it retries or falls back.
Start with the beta.
Hopwire is free during the invite-only beta. Tell us what you send and we will reply by email.