Create a webhook
Register a new webhook endpoint for an application.
Path parameters
Request body
Available events
license.validated, license.created, license.revoked, license.activated, license.hwid_bound, license.hwid_reset, license.deleted, license.expired, license.offline_file_minted
Example
Response (201)
Errors
List webhooks
List all webhooks for an application.
Example
Response (200)
The
secret field is not returned in list responses for security.Update a webhook
Update the URL, events, or enabled status of an existing webhook.
Path parameters
Request body
All fields are optional; only included fields are updated.Example
Response (200)
Delete a webhook
Permanently delete a webhook endpoint.
Example
Response (200)
Test a webhook
Send a test event to the webhook endpoint. Returns the HTTP status code from your server. Requires the
write:webhooks scope.Example
Response (200)
ok is true only for a 2xx response. Redirects are not followed, so a 3xx comes back as ok: false with that status. If AuthForge can’t reach your endpoint (a network error, a timeout, or a blocked host), the response is:
test.ping event, whose data is { "webhookId": ..., "appId": ... }, signed with the webhook’s secret and carrying the same headers as a real delivery. It is not retried. A key with only read:webhooks gets a 403 insufficient_scope, and a webhook ID from another app returns 404 not_found.
Webhook payload format
Every webhook delivery sends an HTTP POST with these headers and body:Headers
Body
data object varies by event type but always includes licenseKey and appId. id is generated once per event and sent again on every retry. Deduplicate on id (or the X-AuthForge-Event-Id header). Retries reuse that id and only change the signature timestamp t.
Signature verification
VerifyX-AuthForge-Signature-V2 and reject deliveries whose t is more than 5 minutes from your clock:
X-AuthForge-Signature header covers only the body and is kept for existing integrations.
See Webhooks for full verification examples in Node.js and Python.