Docs/Guides/Webhooks

Webhooks

Get notified over HTTP instead of polling. Webhook URLs must use https://.

Event types

EventFires when
database.createdA database finishes provisioning successfully.
database.failedA database provisioning job fails.
backup.completedA backup finishes successfully.
backup.failedA backup job fails.
restore.completedA restore-to-new-database finishes successfully.
invoice.paidAn invoice is marked paid.

Create a webhook

curl -X POST https://api.astrabase.app/api/v1/organizations/$ORG_ID/webhooks \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com/hooks/astrabase", "event_types": ["database.created", "backup.completed"]}'

The response includes a secret — like an API key, it's shown once. Save it; GET .../webhooks never returns it again.

Verifying deliveries

Every delivery is a real signed POST with:

  • X-Eminidatabase-Event: the event type, e.g. database.created
  • X-Eminidatabase-Signature: sha256=<hex hmac-sha256 of the exact request body>
import hashlib
import hmac

expected = hmac.new(secret.encode(), body_bytes, hashlib.sha256).hexdigest()
assert hmac.compare_digest(expected, received_signature.removeprefix("sha256="))
import { createHmac, timingSafeEqual } from "node:crypto";

const expected = createHmac("sha256", secret).update(bodyBytes).digest("hex");
const received = receivedSignature.replace("sha256=", "");
const isValid = timingSafeEqual(Buffer.from(expected), Buffer.from(received));

Delivery history

curl https://api.astrabase.app/api/v1/organizations/$ORG_ID/webhooks/$WEBHOOK_ID/deliveries -H "Authorization: Bearer $TOKEN"

Shows every attempt with status and response, useful for debugging an endpoint that isn't receiving events correctly.

Deleting

curl -X DELETE https://api.astrabase.app/api/v1/organizations/$ORG_ID/webhooks/$WEBHOOK_ID -H "Authorization: Bearer $TOKEN"