docs › Guides › Webhooks & HMAC Outgoing Webhooks & HMAC Signatures Receive real-time events from your Aurabase project on your own servers securely using HMAC-SHA256 cryptographic signatures.
8 min read· Level intermediate· Revised on Aug 19, 2026
This English text was generated automatically from the French original and has not been reviewed yet.
# Operation
Webhooks architecture Aurabase outgoing webhooks broadcast system events to your callback URLs (e.g. new user registration, successful payment, table row update).
At-Least-Once Delivery Guarantee
Each webhook sent contains a unique event identifier event_id allowing you to implement idempotent processing on your servers.
Each HTTP POST request issued by Aurabase includes the following security header:
http-headers text
POST /webhook HTTP/1.1
Host: api.votre-domaine.com
Content-Type: application/json
X-Aurabase-Event-Id: evt_01J8Y6Q9K3M7Z...
X-Aurabase-Signature: t=1724060000,v1=9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
# Validation
Verify HMAC-SHA256 signature Node.js / TypeScript Python Go
verify-webhook.ts typescript
import crypto from ' node:crypto'
export function verifyAurabaseWebhook (
rawBody : string , signatureHeader : string , secret : string )
const parts = Object .fromEntries (
signatureHeader .split (' ,' ).map (p => p .split (' =' )),
)
const { t : timestamp , v1 : signature } = parts
// 1. Protection against replay attacks (5 min max)
if (Math .abs (Date .now () / 1000 - Number (timestamp )) > 300 ) {
return false
}
// 2. Calculation of HMAC-SHA256 on timestamp.rawBody
const expected = crypto
.createHmac (' sha256' , secret )
.update (timestamp + ' .' + rawBody )
.digest (' hex' )
// 3. Secure comparison in constant time
return crypto .timingSafeEqual (
Buffer .from (signature ), Buffer .from (expected )
)
}
# Resilience
Fault Management & Dead-Letter Queue If your server responds with an HTTP error code (4xx, 5xx) or experiences a timeout (time limit of 10 seconds), Aurabase automatically retries the sending according to an exponential backoff :
Attempt 1: Immediate
Attempt 2: After 15 seconds
Attempt 3: After 1 minute
Attempt 4: After 5 minutes
Attempt 5: After 30 minutes
After 5 consecutive failures, the event is placed in the Studio's Dead-Letter Queue (DLQ) for inspection and manual replay.
Last updated · Aug 19, 2026