Skip to main content
Webhook Cover Image
Webhooks deliver real-time notifications when events occur in your Dodo Payments account. Use them to automate workflows, update your database, send notifications, and keep your systems in sync.
Dodo Payments webhooks follow the Standard Webhooks specification for signature verification and payload structure.

Key Features

Webhooks provide real-time delivery with built-in security, automatic retries, and event filtering. All official SDKs include signature verification helpers, and the dashboard offers testing, monitoring, and replay tools.

Getting Started

1

Go to Developer → Webhooks

In the Dodo Payments Dashboard, navigate to Developer → Webhooks.
2

Click Add Endpoint

Click Add endpoint to create a new webhook receiver.
3

Enter Your Endpoint URL

Provide the HTTPS URL where Dodo Payments will send webhook events, or select an integration connector (Slack, Discord, Zapier, Resend, etc.) to route events to a third-party service without writing code.
4

Select Events

Choose which events to receive. Events are organized by resource (payment, subscription, dispute, etc.). You can select individual events or an entire resource to receive all related events.
5

Save

Click Create endpoint. Your webhook signing secret appears on the endpoint’s Overview tab.
Keep your webhook secret secure. Never expose it in client-side code or version control.
To rotate your webhook secret, open the endpoint and click Rotate secret next to the secret on the Overview tab. The old secret remains valid for 24 hours after rotation.

Integration Connectors

Route webhook events directly to third-party services using integration connectors, eliminating the need to build and maintain custom webhook handlers.

How Connectors Work

A connector transforms Dodo Payments events into the format the destination expects. Which details you provide depends on the destination: The dashboard shows all connectors available to your business. See External Integrations for what each destination can do with the events.

Setting Up a Connector

When creating or editing an endpoint, select a connector and the side sheet shows setup instructions for that destination. Test the transformation before saving to confirm events are converted correctly.
Use a connector to reach a supported destination without writing code. If you need custom logic, use a standard endpoint with a transformation instead.

Configuring Subscribed Events

Configure which events each webhook endpoint receives.
1

Navigate to Webhook Endpoints

Go to Developer → Webhooks and click on your endpoint.
2

Open Event Configuration

Click Edit to open the endpoint configuration side sheet.
3

Select Events

The event type selector displays all available webhook events organized in a searchable tree, grouped by resource (e.g., payment, subscription, dispute). Check the boxes next to the events you want to receive. You can select individual events, an entire resource, or mix and match.
4

Save Configuration

Click Save to apply your changes.
If you deselect all events, your webhook endpoint receives every event type. Select only the events your application needs.

Event Catalog

Go to Developer → Webhooks and open the Event catalog tab to see every event type Dodo Payments can send. Select an event to view its schema and sample payload.

Webhook Events Guide

Browse events as reference documentation, grouped by resource.

Webhook Delivery

Timeouts

Webhooks में connection और read operations, दोनों के लिए 30-second timeout होता है। Webhooks को asynchronous रूप से process करें और तुरंत 200 status code लौटाएँ, फिर event को background में handle करें।

Automatic Retries

विफल deliveries को exponential backoff के साथ कुल 8 attempts तक दोबारा try किया जाता है: विफल messages को manually replay करने या किसी विशिष्ट time range से messages को bulk में recover करने के लिए dashboard का उपयोग करें।

Idempotency

प्रत्येक webhook में एक unique webhook-id header शामिल होता है। Duplicate events का पता लगाने और उन्हें skip करने के लिए इस ID को store करें, क्योंकि retries के कारण एक ही event कई बार deliver हो सकता है।
हमेशा idempotency checks लागू करें। Retries के कारण आपको एक ही event कई बार प्राप्त हो सकता है।

Event Ordering

Retries या network conditions के कारण events क्रम से बाहर आ सकते हैं। प्रत्येक webhook में एक timestamp field शामिल होता है; यदि आपके application को इसकी आवश्यकता हो, तो events का क्रम निर्धारित करने के लिए इसका उपयोग करें। आपको delivery के समय की latest payload state हमेशा प्राप्त होती है।

Securing Webhooks

Webhook payloads को हमेशा validate करें और HTTPS का उपयोग करें।

Verifying Signatures

प्रत्येक webhook में एक webhook-signature header शामिल होता है: यह payload और timestamp का HMAC SHA256 signature है, जिसे आपकी secret key से sign किया जाता है। सभी official SDKs में built-in helpers शामिल हैं। Client को initialize करते समय DODO_PAYMENTS_WEBHOOK_KEY सेट करें, फिर payload को verify और parse करने के लिए unwrap() call करें। दो methods उपलब्ध हैं:
  • unwrap — आपकी webhook secret key से signature verify करता है, फिर payload को parse करता है।
  • unsafe_unwrap — बिना verification के payload को parse करता है। इसका उपयोग केवल testing के लिए करें।
Method names प्रत्येक language के conventions का पालन करते हैं: TypeScript में unwrap / unsafeUnwrap, Python में unwrap / unsafe_unwrap, और Go में Unwrap / UnsafeUnwrap।
Dodo Payments client को initialize करते समय DODO_PAYMENTS_WEBHOOK_KEY के माध्यम से अपनी webhook secret दें।

Manual Verification (Alternative)

यदि आप SDK का उपयोग नहीं कर रहे हैं, तो signature को स्वयं verify करें:
  1. webhook-id, webhook-timestamp और raw request body को periods से जोड़कर signed content बनाएँ: {id}.{timestamp}.{body}। Raw body को ठीक उसी रूप में उपयोग करें जिस रूप में प्राप्त हुआ है, किसी भी JSON parsing से पहले।
  2. अपनी webhook secret लें। यदि यह whsec_ से शुरू होती है, तो उस prefix को हटाएँ, फिर signing key प्राप्त करने के लिए बाकी हिस्से को base64-decode करें।
  3. Signing key के साथ signed content का HMAC-SHA256 compute करें और परिणाम को base64-encode करें।
  4. webhook-signature header में एक या अधिक space-separated signatures होते हैं, जिनमें प्रत्येक v1,<base64-signature> के रूप में होता है। यदि कोई v1 signature आपके signature से match करता है, तो request valid है। तुलना के लिए constant-time function का उपयोग करें।
  5. Replay attacks को रोकने के लिए यदि webhook-timestamp current time से बहुत अलग हो, तो request reject करें। Standard Webhooks libraries 5 minutes की अनुमति देती हैं।
Reference implementations के लिए Standard Webhooks libraries देखें। Event payload formats के लिए Webhook Payload देखें।

Source IP Addresses

Signature verification समर्थित authentication method है। यह साबित करता है कि request आपकी webhook secret से sign की गई थी, जो network-level check नहीं कर सकता। Webhook deliveries IP addresses के ऐसे pool से आती हैं जो समय के साथ बदलता रहता है। Authentication के लिए IP allowlists पर निर्भर न रहें। इसके बजाय हमेशा webhook-signature header को verify करें, जैसा कि Verifying Signatures में बताया गया है। यदि आपके firewall को allowlist की आवश्यकता है:
  • Addresses को स्थायी रूप से hardcode न करें। Ranges समय के साथ बदलते हैं और पुराने rules deliveries को चुपचाप block कर देते हैं।
  • Firewall को lock down करने से पहले support@dodopayments.com से current ranges का अनुरोध करें।
  • Change notices पर नज़र रखें। जब delivery addresses बदलते हैं, तो हम प्रभावित merchants को email से सूचित करते हैं — बताई गई date से पहले updates लागू करें।
  • आपके द्वारा जोड़े गए network rules के बावजूद signature verification enabled रखें।
Serverless और managed hosting platforms पर inbound IP filtering अक्सर उपलब्ध या व्यावहारिक नहीं होती। इन environments में signature verification सही control है।
Blocked delivery को failure माना जाता है और Automatic Retries में बताए गए schedule के अनुसार retry किया जाता है। यदि firewall rules के कारण deliveries विफल हुई हैं, तो rules ठीक करने के बाद उन्हें दोबारा भेज सकते हैं — Replaying and Recovering Messages देखें।

Responding to Webhooks

Receipt acknowledge करने के लिए आपके webhook handler को 2xx status code लौटाना होगा। किसी भी अन्य response को failure माना जाता है और webhook को retry किया जाएगा।

Best Practices

  • केवल HTTPS का उपयोग करें। HTTP endpoints interception के प्रति vulnerable होते हैं।
  • तुरंत response दें। तुरंत 200 status code लौटाएँ, फिर event को asynchronously process करें।
  • Idempotency लागू करें। Duplicate events का पता लगाने और उन्हें skip करने के लिए webhook-id header का उपयोग करें।
  • अपनी secret को सुरक्षित रखें। DODO_PAYMENTS_WEBHOOK_KEY को environment variables या secrets manager में store करें, कभी भी version control में नहीं।

Webhook Payload Structure

Request Format

Headers

string
आवश्यक
इस webhook event का unique identifier। Idempotency checks के लिए उपयोग करें।
string
आवश्यक
Webhook authenticity verify करने के लिए HMAC SHA256 signature।
string
आवश्यक
Webhook भेजे जाने का Unix timestamp (seconds में)।

Request Body

string
आवश्यक
आपका Dodo Payments business identifier।
string
आवश्यक
इस webhook को trigger करने वाला event type (जैसे, payment.succeeded, subscription.active)।
string
आवश्यक
Event होने का ISO 8601 formatted timestamp।
object
आवश्यक
Event के बारे में विस्तृत जानकारी रखने वाला event-specific payload।

Example Payload

Event Types

सभी उपलब्ध webhook event types ब्राउज़ करें

Event Payloads

प्रत्येक event के लिए detailed payload schemas देखें

Handle Payment Failures

payment.failed पर react करें और declined payments recover करें

Testing Webhooks

Send an Example Event

अपने webhook integration को सीधे dashboard से test करें:
1

Navigate to Webhooks

Developer → Webhooks पर जाएँ और अपने endpoint पर click करें।
2

Open Testing Tab

Testing tab पर click करें।
3

Send Example

कोई event type चुनें और Send example पर click करें। Sample payload आपके endpoint URL पर real event की तरह ही deliver किया जाता है और उसी तरह sign किया जाता है।
4

Check Your Endpoint

Confirm करें कि event पहुँच गया है, आपकी signature verification सफल रही है और आपने 2xx status code लौटाया है।
Testing tab से भेजे गए failed messages को किसी भी अन्य webhook की तरह normal retry schedule के अनुसार retry किया जाता है।

Implementation Example

Webhook verification और handling के साथ complete Express.js implementation:
Production events process करने से पहले dashboard testing interface का उपयोग करके अपने webhook handler को thoroughly test करें। इससे issues को जल्दी पहचानने और ठीक करने में सहायता मिलती है।

Testing Webhooks with the CLI

Dodo Payments CLI में local development के दौरान webhooks test करने के लिए दो commands हैं।

Listen for Live Webhooks Locally

अपने test mode account से वास्तविक webhook events को local development server पर forward करें:
CLI एक WebSocket connection खोलता है और प्रत्येक webhook event को आपके local endpoint (जैसे, http://localhost:3000/webhook) पर forward करता है तथा signature verification testing के लिए सभी headers को सुरक्षित रखता है।
Listener केवल test mode API keys के साथ काम करता है। dodo login चलाएँ और पहले Test Mode चुनें।

Trigger Mock Webhook Events

Real transactions बनाए बिना किसी भी endpoint पर mock webhook payloads भेजें:
यह interactive tool आपको event type चुनने देता है और आपके endpoint पर realistic mock payload भेजता है। यह loop करता है, इसलिए आप एक ही session में कई events test कर सकते हैं। Trigger command subscription, payment, refund, dispute, license key, payout, credit, abandoned checkout, dunning और entitlement grant families को cover करता है। यह subscription.past_due या subscription.unpaused नहीं भेजता। Exact list के लिए Supported Webhook Events देखें।
dodo wh trigger से प्राप्त mock webhook payloads signed नहीं होते। Testing के दौरान अपने webhook handler में unverified parse method (TypeScript में unsafeUnwrap, Python में unsafe_unwrap, Go में UnsafeUnwrap) का ही उपयोग करें।

CLI Webhook Testing Docs

Full CLI webhook testing documentation देखें

Advanced Settings

Advanced tab आपके webhook endpoint behavior को fine-tune करने के लिए अतिरिक्त configuration options प्रदान करता है।

Rate Limiting (Throttling)

आपके endpoint पर webhook events deliver होने की rate नियंत्रित करें। Default रूप से webhooks पर कोई rate limit लागू नहीं होती और events होने के तुरंत बाद deliver किए जाते हैं।
1

Open Advanced Tab

अपने endpoint details page से Advanced tab पर click करें।
2

Configure Rate Limit

Endpoint throttling section को expand करें।
3

Set Your Limit

प्रति second messages की maximum संख्या दर्ज करें, फिर Save पर click करें। इस rate से अधिक deliveries को drop करने के बजाय queue किया जाता है।

Custom Headers

अपने endpoint पर भेजे जाने वाले सभी webhook requests में custom HTTP headers जोड़ें। यह authentication, routing या metadata जोड़ने के लिए उपयोगी है।
1

Add Headers

Custom headers section में header name और value दर्ज करें।
2

Add Multiple Headers

प्रत्येक अतिरिक्त header के लिए Add header पर click करें, फिर Save पर click करें।

Transformations

Transformations आपको webhook payload को modify करने और वैकल्पिक रूप से उसे किसी अलग URL पर redirect करने देती हैं। Transformations का उपयोग करें:
  • Processing से पहले payload structure modify करने के लिए
  • Content के आधार पर webhooks को अलग-अलग endpoints पर route करने के लिए
  • Payload में fields जोड़ने या हटाने के लिए
  • Data formats transform करने के लिए
1

Enable Transformations

Transformation section में Enable transformation को on करें।
2

Configure Transformation

Code editor में अपनी transformation rules JavaScript में लिखें, फिर Save पर click करें। Code को handler() से webhook object return करना होगा।
3

Test Transformation

Live होने से पहले यह verify करने के लिए transformation test interface का उपयोग करें कि आपकी transformation सही ढंग से काम करती है।
Transformations webhook delivery performance को प्रभावित कर सकती हैं। Thoroughly test करें और transformation logic को simple तथा efficient रखें।

Monitoring Webhook Logs

Logs tab आपके webhook delivery status की visibility प्रदान करता है।
1

Navigate to Logs Tab

Developer → Webhooks पर जाएँ और Logs tab खोलें।
2

Browse Delivery History

सभी webhook delivery attempts की table देखें, जिसमें Event type, Message ID, Event ID, Sent at, Attempted at, Response code और Duration columns हैं।
3

Search and Filter

ID या event type के आधार पर specific messages खोजने के लिए search bar का उपयोग करें। आवश्यक events पर ध्यान केंद्रित करने के लिए status (Succeeded, Failed, Pending आदि) से filter करें।
4

View Message Details

Message detail page खोलने के लिए किसी message पर click करें, जिसमें दिखाई देता है:
  • Complete webhook payload
  • Response code और duration के साथ प्रत्येक delivery attempt
  • प्रत्येक attempt का timestamp
  • आपके endpoint से प्राप्त कोई भी error messages
प्रत्येक attempt में एक Replay action होता है, जिससे page छोड़े बिना उस message को दोबारा भेजा जा सकता है।

Activity Monitoring

अपने endpoints पर delivery performance देखने के लिए Developer → Webhooks पर जाएँ और Activity tab खोलें। Delivery activity समय के साथ attempts को plot करता है, जिन्हें window के आधार पर Attempts per 5 minutes, Attempts per hour या Attempts per day में bucket किया जाता है। प्रत्येक bar outcome के अनुसार विभाजित होती है और किसी segment पर hover करने से status, attempts की संख्या और total में उसका share दिखाई देता है। किसी endpoint पर Overview tab में Delivery stats (last 24h) पिछले दिन की यही जानकारी summarize करता है।
Endpoints tab का Error rate (24h) column तुरंत दिखाता है कि किन endpoints पर ध्यान देने की आवश्यकता है।

Replaying and Recovering Messages

किसी message को दोबारा भेजने का तरीका इस बात पर निर्भर करता है कि आपको कितने messages की आवश्यकता है:
  • One message — इसे Logs tab से खोलें और attempt पर Replay action का उपयोग करें।
  • A range of messages — endpoint खोलें, क्योंकि bulk modes एक समय में केवल एक endpoint पर काम करते हैं।

Replaying in Bulk

Developer → Webhooks से endpoint खोलें। तीन modes उपलब्ध हैं और प्रत्येक केवल उसी endpoint पर काम करता है:
1

Open More Actions

Endpoint पर More actions खोलें और ऊपर दिए गए तीन modes में से एक चुनें।
2

Set the Range

Table में सूचीबद्ध mode के अनुसार माँगी गई range भरें।
3

Start the Run

चुने गए mode के अनुसार Recover या Replay पर click करें।
प्रत्येक run endpoint के Overview tab में Replay history के अंतर्गत दिखाई देता है, जिसमें उसका mode, time range, status और दोबारा भेजे गए messages की संख्या शामिल होती है।

Email Alerts

Webhooks dashboard विफल deliveries के लिए email alerts प्रदान नहीं करता। Deliveries monitor करने के लिए Developer → Webhooks पर जाएँ और Logs तथा Activity tabs देखें।

Deploy to Cloud Platforms

Popular cloud providers पर webhook handlers deploy करने के लिए platform-specific guides:

Vercel

Vercel पर serverless functions के साथ webhooks deploy करें

Cloudflare Workers

Cloudflare के edge network पर webhooks चलाएँ

Supabase Edge Functions

Webhooks को Supabase के साथ integrate करें

Netlify Functions

Webhooks को Netlify serverless functions के रूप में deploy करें

Create Webhook

Webhook endpoints को programmatically create और configure करें

List Webhooks

अपने webhook endpoints को retrieve और manage करें
अंतिम संशोधन 26 सितंबर 2026