Webhook (JSON) delivers each identity event as a signed JSON body to an HTTPS endpoint. The channel type in the console is **Webhook**. The body is JSON. You verify it before you trust it.

## Add the channel

In the [Authdog console](https://console.authdog.com):

1. Select the project and environment.
2. Open **Notifications > Channels**.
3. Select **Add Channel**.
4. Set **Channel Type** to **Webhook** and name the channel.
5. Paste an HTTPS URL that accepts `POST` with `Content-Type: application/json`.
6. Choose triggers, or leave the event list empty to drain every event.
7. Save and send a test.

The URL is stored as a secret and shown redacted after save. Open the channel and copy **Signing secret** (`whsec_…`). **Rotate** invalidates the previous secret immediately.

A `2xx` is success. Anything else is retried with backoff starting at 60 seconds, for at most five attempts.

## Read the JSON safely

Each delivery sets:

| Header | Use |
| --- | --- |
| `X-Authdog-Signature` | `t=<unix>, v1=<hex>` |
| `X-Authdog-Event-Type` | The event name, so you can route before a deep parse |
| `X-Authdog-Delivery-Id` | Deduplicate retries and manual redelivery |

Verification order:

1. Read the raw request body before JSON parsing.
2. Parse `t` and `v1` from `X-Authdog-Signature`.
3. Reject timestamps outside your replay window.
4. Compute HMAC-SHA256 over the bytes of `t + "." + rawBody` with the channel signing secret.
5. Compare digests in constant time.
6. Only then parse the JSON and branch on `X-Authdog-Event-Type`.

Store the delivery ID. The same logical event can arrive more than once.

## Test it

1. Send the test delivery and log the raw body plus the three headers.
2. Confirm your verifier accepts that body and rejects a body you alter by one byte.
3. Trigger a sign-in in the same environment and confirm the event type matches what you subscribed to.

Repeat the channel in production with a production URL and secret. Channels do not copy between environments.

## Related

| Read | To learn how to |
| --- | --- |
| [Webhooks](/marketplace/webhooks/setup) | Channel setup, triggers, and retries |
| [Events and webhooks](/docs/events-webhooks) | The event catalog and delivery records |
| [Marketplace](/marketplace/webhooks-json) | The listing for this integration |
