Skip to main content
Manage webhook endpoints that receive real-time notifications when license events occur.

Create a webhook

Register a new webhook endpoint for an application.

Path parameters

Request body

Available events

license.validated, license.created, license.revoked, license.activated, license.hwid_bound, license.hwid_reset, license.deleted, license.expired, license.offline_file_minted

Example

Response (201)

The secret field is returned only on creation. Store it securely; you’ll need it to verify webhook signatures. It cannot be retrieved again.

Errors


List webhooks

List all webhooks for an application.

Example

Response (200)

The secret field is not returned in list responses for security.

Update a webhook

Update the URL, events, or enabled status of an existing webhook.

Path parameters

Request body

All fields are optional; only included fields are updated.

Example

Response (200)


Delete a webhook

Permanently delete a webhook endpoint.

Example

Response (200)


Test a webhook

Send a test event to the webhook endpoint. Returns the HTTP status code from your server. Requires the write:webhooks scope.

Example

Response (200)

ok is true only for a 2xx response. Redirects are not followed, so a 3xx comes back as ok: false with that status. If AuthForge can’t reach your endpoint (a network error, a timeout, or a blocked host), the response is:
The test sends one test.ping event, whose data is { "webhookId": ..., "appId": ... }, signed with the webhook’s secret and carrying the same headers as a real delivery. It is not retried. A key with only read:webhooks gets a 403 insufficient_scope, and a webhook ID from another app returns 404 not_found.

Webhook payload format

Every webhook delivery sends an HTTP POST with these headers and body:

Headers

Body

The data object varies by event type but always includes licenseKey and appId. id is generated once per event and sent again on every retry. Deduplicate on id (or the X-AuthForge-Event-Id header). Retries reuse that id and only change the signature timestamp t.

Signature verification

Verify X-AuthForge-Signature-V2 and reject deliveries whose t is more than 5 minutes from your clock:
The legacy X-AuthForge-Signature header covers only the body and is kept for existing integrations. See Webhooks for full verification examples in Node.js and Python.