Webhooks & Events

Every sign-up, payment and plan change, signed and posted to your server.

Pick from 112 events and point them at an HTTPS endpoint, and BuildBase POSTs a signed JSON body each time one fires. One SDK call verifies the signature and parses the event, and the console shows every delivery attempt.

Your app is an organization in BuildBase. Your users sign in and work inside workspaces - one per team or customer.

You set up

In the console and the SDK

  • The address on your server that receives events
  • Which events you want to hear about
  • One call on your server to check each event is really from us

You get

For you and your team

  • Sign-ups, payments and plan changes, sent to your server as they happen
  • Retries when your server is briefly down
  • A log of every delivery in the console

Events your backend can trust

Signed, retried and logged, so a missed payment or a new member reaches your system without you polling.

Choose Your Events

112 events - sign-ups, payments, plan changes, credits, workflows and more. Pick the ones you need, or all of them.

Signed So You Can Trust It

Every event is signed. One call on your server checks the signature and hands you the event.

Retried if You Miss It

If your server is down or errors, the event is sent again with growing gaps between tries.

Every Delivery Logged

See each attempt, its result and how long it took, in the console.

Details Included

Events carry the full workspace, user, subscription and plan, so you rarely need to look anything up.

Safe by Default

Only HTTPS addresses are accepted, and an address that keeps failing is paused until you turn it back on.

Verify and handle in one call

parseWebhookEvent() checks the signature and timestamp and returns { event, timestamp, data }, or null if anything is wrong.

app/api/webhooks/route.tsTSX
import { parseWebhookEvent } from '@buildbase/sdk';

export async function POST(req) {
  const body = await req.text();

  // Verifies the signature and parses the payload — returns null on failure
  const parsed = parseWebhookEvent({
    body,
    signature: req.headers.get('x-buildbase-signature'),
    timestamp: req.headers.get('x-buildbase-timestamp'),
    secret: process.env.WEBHOOK_SECRET,
  });

  if (!parsed) {
    return Response.json({ error: 'Invalid signature' }, { status: 401 });
  }

  switch (parsed.event) {
    case 'subscription.upgraded':
      await enablePremiumFeatures(parsed.data.workspaceId);
      break;
    case 'credit.low_balance':
      await notifyTeam(parsed.data.workspaceId);
      break;
    case 'workspace.member_added':
      await syncToExternalCRM(parsed.data);
      break;
  }

  return Response.json({ received: true });
}

Frequently Asked Questions

What people ask about Webhooks.

Do my users see this?

No. Webhooks send events to your server so your backend can react.

Which events can I receive?

112, across users, workspaces, subscriptions, payments, credits, workflows, audience, email and more. Subscribe each endpoint to the ones it needs, or to all of them.

How do I know an event is really from you?

Every event is signed. parseWebhookEvent() checks the signature and the timestamp and gives you the event, or null if anything is wrong.

Can an event arrive twice or out of order?

Yes. Delivery is at-least-once with no ordering guarantee, so deduplicate on a hash of the raw body.

Can I send a test event or replay one?

No. There is no test or resend button - the delivery log shows every real attempt.

Send your first event to your own server

Add an endpoint in the console, copy the signing secret, and drop parseWebhookEvent() into a route. The next sign-up arrives signed.

7-day free trialNo credit card requiredCancel anytime