Every sign-up, payment and plan change, signed and posted to your server.
Pick from 112 events and point them at an HTTPS endpoint, and BuildBase POSTs a signed JSON body each time one fires. One SDK call verifies the signature and parses the event, and the console shows every delivery attempt.
Your app is an organization in BuildBase. Your users sign in and work inside workspaces - one per team or customer.
You set up
In the console and the SDK
- The address on your server that receives events
- Which events you want to hear about
- One call on your server to check each event is really from us
You get
For you and your team
- Sign-ups, payments and plan changes, sent to your server as they happen
- Retries when your server is briefly down
- A log of every delivery in the console
Events your backend can trust
Signed, retried and logged, so a missed payment or a new member reaches your system without you polling.
Choose Your Events
112 events - sign-ups, payments, plan changes, credits, workflows and more. Pick the ones you need, or all of them.
Signed So You Can Trust It
Every event is signed. One call on your server checks the signature and hands you the event.
Retried if You Miss It
If your server is down or errors, the event is sent again with growing gaps between tries.
Every Delivery Logged
See each attempt, its result and how long it took, in the console.
Details Included
Events carry the full workspace, user, subscription and plan, so you rarely need to look anything up.
Safe by Default
Only HTTPS addresses are accepted, and an address that keeps failing is paused until you turn it back on.
Verify and handle in one call
parseWebhookEvent() checks the signature and timestamp and returns { event, timestamp, data }, or null if anything is wrong.
import { parseWebhookEvent } from '@buildbase/sdk';
export async function POST(req) {
const body = await req.text();
// Verifies the signature and parses the payload — returns null on failure
const parsed = parseWebhookEvent({
body,
signature: req.headers.get('x-buildbase-signature'),
timestamp: req.headers.get('x-buildbase-timestamp'),
secret: process.env.WEBHOOK_SECRET,
});
if (!parsed) {
return Response.json({ error: 'Invalid signature' }, { status: 401 });
}
switch (parsed.event) {
case 'subscription.upgraded':
await enablePremiumFeatures(parsed.data.workspaceId);
break;
case 'credit.low_balance':
await notifyTeam(parsed.data.workspaceId);
break;
case 'workspace.member_added':
await syncToExternalCRM(parsed.data);
break;
}
return Response.json({ received: true });
}Read more in the docs
Setup guides and reference for Webhooks & Events.
Overview
112 subscribable events with signatures, retries and delivery logs.
Server SDK
Node.js SDK for backend operations - usage recording, credit consumption, notifications, and more.
Workflow triggers and actions
The full catalog of workflow triggers, actions, and conditions with their inputs and outputs.
Billing
Add subscription plans, checkout, trials, and seat-based pricing to your app.
Frequently Asked Questions
What people ask about Webhooks.
Do my users see this?
No. Webhooks send events to your server so your backend can react.
Which events can I receive?
112, across users, workspaces, subscriptions, payments, credits, workflows, audience, email and more. Subscribe each endpoint to the ones it needs, or to all of them.
How do I know an event is really from you?
Every event is signed. parseWebhookEvent() checks the signature and the timestamp and gives you the event, or null if anything is wrong.
Can an event arrive twice or out of order?
Yes. Delivery is at-least-once with no ordering guarantee, so deduplicate on a hash of the raw body.
Can I send a test event or replay one?
No. There is no test or resend button - the delivery log shows every real attempt.