Webhooks

Register an endpoint from your dashboard's Developers page, or via POST /v1/webhook-endpoints, and choose which event types it receives.

Verifying a signature

Every delivery carries an X-Signature header:

t=<unix timestamp>,v1=<hex HMAC-SHA256(secret, t + "." + body)>

Recompute the HMAC over the timestamp and raw body using your endpoint's secret (shown once, at creation), compare it to v1 with a constant-time comparison, and reject anything older than 300 seconds.

Retries

A delivery that doesn't return a 2xx within 10s is retried on a backoff schedule, up to 8 times: 10s, 60s, 300s, 1800s, 7200s, 21600s, 43200s, 86400s. An endpoint that keeps failing is auto-disabled and you'll be alerted. Every delivery attempt is logged and replayable from GET /v1/events.

Event types

Subscription

  • subscription.created
  • subscription.activated
  • subscription.past_due
  • subscription.paused
  • subscription.resumed
  • subscription.canceled
  • subscription.reactivated
  • subscription.ended
  • subscription.item_added
  • subscription.item_changed
  • subscription.item_removed

Invoice

  • invoice.created
  • invoice.paid
  • invoice.overdue
  • invoice.payment_failed

Payment

  • payment.succeeded
  • payment.failed
  • payment.recorded

Customer

  • customer.created
  • customer.updated

Trial

  • trial.will_end