Skip to main content
Webhooks send HTTP POST requests to your server when events happen on your licenses; creation, validation, revocation, and more. Use them to sync license state with your backend, trigger workflows, or update your database.

How it works

  1. You register a webhook URL in the dashboard or via the API.
  2. When a matching event occurs, AuthForge sends an HTTP POST to your URL with a JSON payload.
  3. Each request is signed with HMAC-SHA256 so you can verify it came from AuthForge.

Events

license.validated fires on every successful SDK login. For high-traffic apps, consider subscribing only to the events you need.

Payload format

Every webhook delivery sends a JSON body like this:

Headers

Signature verification

Every webhook is signed using the secret generated when you created the webhook. Always verify the signature before processing. Verify X-AuthForge-Signature-V2. It signs the send time together with the body, so an attacker who captures a delivery can’t replay it later or change its timestamp:
To verify:
  1. Split the header on , and read the t and v1 values.
  2. Reject the request if t is more than 5 minutes away from your current time.
  3. Compute HMAC-SHA256 of the string <t>. followed by the raw request body (the exact bytes you received, before JSON parsing), keyed by your webhook secret.
  4. Compare your hex digest with v1 using a constant-time comparison.
Retries resend the same body with a fresh t, so the V2 header differs between attempts. Deduplicate on the body’s id (also sent as X-AuthForge-Event-Id). Retries reuse that id and only change t.

Verification example (Node.js / Express)

Verification example (Python / Flask)

Legacy signature (X-AuthForge-Signature)

X-AuthForge-Signature is still sent on every delivery so existing integrations keep working. It is sha256= followed by HMAC-SHA256 of the raw body alone, which means it doesn’t cover X-AuthForge-Timestamp: a captured request can be replayed, or its timestamp changed, without breaking the signature. Switch to X-AuthForge-Signature-V2 when you can.

Setup

Via the dashboard

  1. Go to your app’s Settings → Webhooks
  2. Click Add Webhook
  3. Enter your HTTPS endpoint URL
  4. Select which events to subscribe to (or select all)
  5. Click Create
  6. Copy the webhook secret: it’s shown only once

Via the Developer API

The response includes a secret field; store it securely for signature verification.

Limits

Testing

Use the test endpoint to send a sample payload to your webhook URL:
This sends a signed test.ping event to verify your endpoint is receiving and verifying payloads correctly.

Next steps