Skip to main content

Create a subscription

  1. Select the intended workspace and open Integrations → Webhooks.
  2. Add a public HTTPS endpoint and choose the exact event types.
  3. Save the endpoint and securely obtain its signing secret from endpoint management.
  4. Send a test event and inspect its delivery log.
Workspace owner/admin permissions govern subscription management. Keep the endpoint signing secret separate from SendPilot API keys and Clerk credentials.

Verify a receiver

Install the libraries in your receiver application:
This minimal Express example verifies the delivery and logs its identifiers. In a production receiver, replace the log with a durable, idempotent enqueue/processing step before acknowledging success.
Do not JSON-parse and re-serialize the body before verifying it. The library validates the signature and timestamp and supports multiple signatures during key rotation. Follow the provider’s actual rotation overlap; do not assume a fixed 24-hour overlap.

Process events reliably

  • Deduplicate using eventId before applying side effects.
  • Validate the expected workspace and event type in your application.
  • Make downstream updates idempotent; a delivery can be retried after a timeout.
  • Return a non-2xx response if the event cannot be safely accepted for processing.
  • Use current API state when an event alone is insufficient to resolve an outcome.
For local development, a public HTTPS tunnel can forward deliveries to your local receiver. Use test data and your own endpoint; switch the subscription to its production destination when ready.

Manage deliveries and subscriptions

Use Integrations → Webhooks and its available endpoint management/delivery controls to test, inspect failures, update event filters, disable or delete an endpoint. Deleting a subscription does not recall events already delivered. Signature verification details and supported frameworks are documented by Svix.