GitHub Repository
Complete source code and setup guide
Quick Setup
1. Prerequisites
You need:- A Supabase account with a project created
- A Dodo Payments API key from Developer β API Keys in the dashboard
2. Authenticate & Link
3. Database Setup
- Go to the Supabase dashboard.
- Open the SQL Editor.
- Copy the entire contents of
schema.sqland run it.
4. Set Initial Secrets
Supabase automatically providesSUPABASE_URL and SUPABASE_SERVICE_ROLE_KEY at runtime.
Youβll set
DODO_PAYMENTS_WEBHOOK_KEY after deployment, once you have your webhook URL.5. Deploy
The function is already set up infunctions/webhook/index.ts.
6. Get Your Webhook URL
Your webhook URL is:7. Register Webhook in DodoPayments Dashboard
- Go to Developer β Webhooks in the Dodo Payments dashboard.
- Click Add endpoint.
- Enter your webhook URL.
- Select these events:
subscription.active,subscription.cancelled,subscription.renewed. - Click Create endpoint and copy the signing secret.
8. Set Webhook Key & Redeploy
What It Does
The webhook handler processes subscription events and stores them in Supabase PostgreSQL:subscription.activeβ Creates or updates customer and subscription recordssubscription.cancelledβ Marks the subscription as cancelledsubscription.renewedβ Updates the next billing date
Key Features
- Signature verification β Uses the Dodo Payments SDK to verify webhook authenticity
- Idempotency β Uses the
webhook-idheader to prevent duplicate processing - Event logging β Stores all events in the
webhook_eventstable for audit trails - Error handling β Logs failures and marks events for retry
This example handles three core subscription events with minimal fields. You can extend it to support additional event types and fields based on your needs.
Configuration Files
Database Schema
customersβ Email, name, and Dodo Payments customer IDsubscriptionsβ Status, amount, next billing date, linked to customerswebhook_eventsβ Event log with webhook ID for idempotency
Implementation Code
How It Works
The Deno-based Edge Function:- Verifies the signature β Uses the Dodo Payments SDK for HMAC-SHA256 verification
- Checks for duplicates β Uses the
webhook-idheader to prevent duplicate processing - Logs the event β Stores the raw webhook data in the
webhook_eventstable - Processes updates β Creates or updates customers and subscriptions via the Supabase client
- Handles errors β Logs failures and marks events for retry
Testing
Local development:The
--no-verify-jwt flag is required because webhooks donβt include JWT tokens. Security is provided by webhook signature verification.- Go to Developer β Webhooks.
- Add an endpoint with your Supabase URL.
- Select
subscription.active,subscription.cancelled, andsubscription.renewed.