How it works
- You register a webhook URL in the dashboard or via the API.
- When a matching event occurs, AuthForge sends an HTTP POST to your URL with a JSON payload.
- Each request is signed with HMAC-SHA256 so you can verify it came from AuthForge.
Events
license.validated fires on every successful SDK login. For high-traffic apps, consider subscribing only to the events you need.Payload format
Every webhook delivery sends a JSON body like this:Headers
Signature verification
Every webhook is signed using the secret generated when you created the webhook. Always verify the signature before processing. VerifyX-AuthForge-Signature-V2. It signs the send time together with the body, so an attacker who captures a delivery can’t replay it later or change its timestamp:
- Split the header on
,and read thetandv1values. - Reject the request if
tis more than 5 minutes away from your current time. - Compute HMAC-SHA256 of the string
<t>.followed by the raw request body (the exact bytes you received, before JSON parsing), keyed by your webhook secret. - Compare your hex digest with
v1using a constant-time comparison.
Retries resend the same body with a fresh
t, so the V2 header differs between attempts. Deduplicate on the body’s id (also sent as X-AuthForge-Event-Id). Retries reuse that id and only change t.Verification example (Node.js / Express)
Verification example (Python / Flask)
Legacy signature (X-AuthForge-Signature)
X-AuthForge-Signature is still sent on every delivery so existing integrations keep working. It is sha256= followed by HMAC-SHA256 of the raw body alone, which means it doesn’t cover X-AuthForge-Timestamp: a captured request can be replayed, or its timestamp changed, without breaking the signature. Switch to X-AuthForge-Signature-V2 when you can.
Setup
Via the dashboard
- Go to your app’s Settings → Webhooks
- Click Add Webhook
- Enter your HTTPS endpoint URL
- Select which events to subscribe to (or select all)
- Click Create
- Copy the webhook secret: it’s shown only once
Via the Developer API
secret field; store it securely for signature verification.
Limits
Testing
Use the test endpoint to send a sample payload to your webhook URL:test.ping event to verify your endpoint is receiving and verifying payloads correctly.
Next steps
- Webhooks API Reference; Full endpoint documentation
- Commerce; Stripe checkout into licenses; subscribe to
license.createdfor your own fulfilment