Skip to main content
You register a webhook endpoint in one of three places. The Events tab and the App Manifest register destinations for your app as a whole, and the API registers one on behalf of the creator whose access token you send. Whichever you use, an endpoint receives an event only when a destination exists for the topic and the consenting token holds the topic’s scope. Before you register, make sure your endpoint answers the verification probe and checks signatures. The complete receiver does both in one Express handler, or you can mount the Builder SDK’s webhook receiver.

Scope per family

Scopes and webhook events lists the scope of every topic.

Events tab

The Events tab of your app in the Developer Area holds one destination per event type. Creators who authorised your app before you added a scope must authorise it again before the new events are delivered. Checkout events appear in the picker for accounts that have checkout links enabled.

App Manifest

webhooks.destinations[] in app-manifest.json declares the same destinations as a list of { "topic": "...", "url": "..." } objects. The schema is under webhooks in the manifest reference.

API

POST /webhooks/subscriptions creates a destination on behalf of the creator whose access token you send. 49 events are subscribable through the API, every Creator, Checkout and Legacy topic in the Event catalogue. app.* events are not.
Every subscribe call mints a new destination with its own secret, even for the same URL and creator. Keep a secret per subscription id and select the right one when verifying. Deleting one subscription does not affect the secrets of the others. Configure webhooks on a creator’s Checkout Links page offers two routes. No-code (Zapier) opens the Zapier guide, and Code (create an app) opens the Developer Area. Zapier subscribes and unsubscribes through the API on the creator’s behalf and verifies signatures itself, so a creator using Zapier manages no URL or secret.

Test a destination

The Events tab and the API each send a synthetic event to a destination. Test payloads carry TEST- prefixed ids inside data. The envelope id is random, and the API returns it. Test payloads also populate purchaser.email and transaction_id on payment events. Production creator.payment.* deliveries set both to null, so don’t build on either field there. Production checkout_link.payment.* deliveries carry the real values when Fanvue has them.