Skip to main content
System Webhook Events deliver webhook notifications to your server when connections change or Dynamic Rules updates are available. Use them to react immediately without polling.

Quick Reference

Configuration

Configure System Webhook Events in the OFAuth Dashboard:
  • Set your webhook endpoint URL
  • Choose which events to subscribe to
  • Review delivery history and failures

Connections Guide

Learn how to store and manage connection IDs

Error Handling

Handle delivery failures and retries

Event References

Connection Events

connection.created, connection.updated, connection.expired, and connection.disconnected

System Events

rules.updated and Dynamic Rules change notifications

Delivery & Retries

  • Retry policy: exponential backoff with up to 5 attempts
  • Timeout: 10 seconds per request
  • Ordering: in-order delivery per connection ID
Your endpoint should return a 2xx response within 10 seconds.

Signature Verification

System Webhook Events uses Svix signing. Every delivery includes these headers:
Verify requests by:
  1. Read the raw request body before parsing JSON.
  2. Pass the raw body, svix-id, svix-timestamp, and svix-signature headers to a Svix webhook verifier.
  3. Use the signing secret from the OFAuth Dashboard.
  4. Use svix-id as the delivery ID for deduplication.
Use the Svix headers only. Do not implement a separate HMAC format. The Svix verifier checks the timestamp and signature for you.

Implementation Checklist

  1. Parse the application/json body
  2. Verify the signature before processing
  3. Route the event by type
  4. Return 2xx within 10 seconds
  5. Make handlers idempotent by storing processed svix-id values

Troubleshooting

Ensure your endpoint is publicly reachable and returns a 2xx response within 10 seconds.
Verify the endpoint URL and selected subscriptions in the Dashboard.
Use the raw request body and a Svix webhook verifier. Confirm that the endpoint uses the signing secret shown in the Dashboard and reads the svix-id, svix-timestamp, and svix-signature headers.

Next Steps

Connection Events

Connection lifecycle payloads and examples

System Events

rules.updated deliveries and Dynamic Rules guidance