Aurabase Logo
aurabasedocs
docs›Guides›Webhooks & HMAC

Outgoing Webhooks & HMAC Signatures

Receive real-time events from your Aurabase project on your own servers securely using HMAC-SHA256 cryptographic signatures.

8 min read·Level intermediate·Revised on Aug 19, 2026
This English text was generated automatically from the French original and has not been reviewed yet.
#
Operation

Webhooks architecture

Aurabase outgoing webhooks broadcast system events to your callback URLs (e.g. new user registration, successful payment, table row update).

At-Least-Once Delivery Guarantee

Each webhook sent contains a unique event identifier event_id allowing you to implement idempotent processing on your servers.

#
Security

Structure of the X-Aurabase-Signature header

Each HTTP POST request issued by Aurabase includes the following security header:

http-headerstext
POST /webhook HTTP/1.1
Host: api.votre-domaine.com
Content-Type: application/json
X-Aurabase-Event-Id: evt_01J8Y6Q9K3M7Z...
X-Aurabase-Signature: t=1724060000,v1=9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
#
Validation

Verify HMAC-SHA256 signature

verify-webhook.tstypescript
import crypto from 'node:crypto'
export function verifyAurabaseWebhook(
  rawBody: string, signatureHeader: string, secret: string)
  const parts = Object.fromEntries(
    signatureHeader.split(',').map(p => p.split('=')),
  )
  const { t: timestamp, v1: signature } = parts

  // 1. Protection against replay attacks (5 min max)
  if (Math.abs(Date.now() / 1000 - Number(timestamp)) > 300) {
    return false
  }

  // 2. Calculation of HMAC-SHA256 on timestamp.rawBody
  const expected = crypto
    .createHmac('sha256', secret)
    .update(timestamp + '.' + rawBody)
    .digest('hex')

  // 3. Secure comparison in constant time
  return crypto.timingSafeEqual(
    Buffer.from(signature), Buffer.from(expected)
  )
}
#
Resilience

Fault Management & Dead-Letter Queue

If your server responds with an HTTP error code (4xx, 5xx) or experiences a timeout (time limit of 10 seconds), Aurabase automatically retries the sending according to an exponential backoff:

  • Attempt 1: Immediate
  • Attempt 2: After 15 seconds
  • Attempt 3: After 1 minute
  • Attempt 4: After 5 minutes
  • Attempt 5: After 30 minutes

After 5 consecutive failures, the event is placed in the Studio's Dead-Letter Queue (DLQ) for inspection and manual replay.

Last updated · Aug 19, 2026