Skip to main content
Webhooks tell your app what happened without polling. Postbase sends an HTTP POST to your endpoint when a post finishes publishing or a channel loses access.

Events

A post sends one final event, with every channel’s result in it. A failed channel that Postbase is still retrying on its own doesn’t send an event yet. If you retry a post later, its new outcome sends a new event.

Add an endpoint

In Postbase, open Developers → Webhooks, enter an https:// URL and pick the events. Or use the API:
The response includes the endpoint’s signing secret (whsec_…). It’s shown once, so store it. A workspace can have up to 10 endpoints.

The request

data.post has the same shape as GET /posts/{id}. For channel.needs_reconnect, data.channel has the channel’s id, platform, handle and the error.

Verify the signature

Check every request before trusting it:
  1. Read the raw request body as text. Don’t parse and re-serialize it first.
  2. Compute HMAC-SHA256 of <Postbase-Timestamp>.<raw body> with your secret, as hex, and prefix it with sha256=.
  3. Compare it with Postbase-Signature in constant time.
  4. Reject timestamps more than 5 minutes old, so a captured request can’t be replayed.
Node.js
Python

Delivery and retries

Return any 2xx within 10 seconds; do slow work afterwards. Anything else (including a timeout or a redirect) counts as a failure and is retried after 1 minute, 5 minutes, 30 minutes, 2 hours and 6 hours, then marked failed. You can see every attempt with GET /webhooks/{id} or on the Developers page. The same event can arrive more than once (for example if your endpoint saved it but answered slowly). Store the event id and skip ones you’ve already handled. Endpoints must be public https:// URLs. Private and internal addresses are refused.