The channel type in the console is Webhook. The body is JSON. You verify it before you trust it.
Add the channel
In the Authdog console:
- Select the project and environment.
- Open Notifications > Channels.
- Select Add Channel.
- Set Channel Type to Webhook and name the channel.
- Paste an HTTPS URL that accepts
POSTwithContent-Type: application/json. - Choose triggers, or leave the event list empty to drain every event.
- Save and send a test.
The URL is stored as a secret and shown redacted after save. Open the channel and copy Signing secret (whsec_…). Rotate invalidates the previous secret immediately.
A 2xx is success. Anything else is retried with backoff starting at 60 seconds, for at most five attempts.
Read the JSON safely
Each delivery sets:
| Header | Use |
|---|---|
X-Authdog-Signature |
t=<unix>, v1=<hex> |
X-Authdog-Event-Type |
The event name, so you can route before a deep parse |
X-Authdog-Delivery-Id |
Deduplicate retries and manual redelivery |
Verification order:
- Read the raw request body before JSON parsing.
- Parse
tandv1fromX-Authdog-Signature. - Reject timestamps outside your replay window.
- Compute HMAC-SHA256 over the bytes of
t + "." + rawBodywith the channel signing secret. - Compare digests in constant time.
- Only then parse the JSON and branch on
X-Authdog-Event-Type.
Store the delivery ID. The same logical event can arrive more than once.
Test it
- Send the test delivery and log the raw body plus the three headers.
- Confirm your verifier accepts that body and rejects a body you alter by one byte.
- Trigger a sign-in in the same environment and confirm the event type matches what you subscribed to.
Repeat the channel in production with a production URL and secret. Channels do not copy between environments.
Related
| Read | To learn how to |
|---|---|
| Webhooks | Channel setup, triggers, and retries |
| Events and webhooks | The event catalog and delivery records |
| Marketplace | The listing for this integration |