Skip to content
Français

createStandardWebhook

import { createStandardWebhook } from "@elie-laloum/outpost";

Create a trigger source for senders that follow the Standard Webhooks scheme. It verifies every v1 signature of webhook-signature over id.timestamp.body with whsec_ secrets within a timestamp window, uses webhook-id as delivery and the payload type field, or webhook, as kind. It reports no actor.

Complete example and detailed rules.

  • optionsRequired
    StandardWebhookOptions
    Signing secret, timestamp window and source name.
  • options.secretRequired
    TriggerSecret
    whsec_ secret verifying webhook-signature, or a callback returning every currently accepted secret (old and new during a rotation). An empty string throws at creation; a callback that fails or returns nothing, or a secret without the whsec_ prefix, denies requests.
  • options.toleranceMsOptional
    number | undefined
    Accepted clock difference for the request timestamp, in milliseconds; defaults to 300000 (5 minutes). A value that is not a positive integer throws at creation.
  • options.sourceOptional
    string | undefined
    Name reported in TriggerEvent.source; defaults to standard.

TriggerSource

export declare function createStandardWebhook(
  options: StandardWebhookOptions,
): TriggerSource;