POST to your endpoint when a post finishes publishing or a channel loses
access.
Events
A post sends one final event, with every channel’s result in it. A failed
channel that Postbase is still retrying on its own doesn’t send an event yet.
If you retry a post later, its new outcome sends a new event.
Add an endpoint
In Postbase, open Developers → Webhooks, enter anhttps:// URL and pick
the events. Or use the API:
whsec_…). It’s shown
once, so store it. A workspace can have up to 10 endpoints.
The request
data.post has the same shape as GET /posts/{id}.
For channel.needs_reconnect, data.channel has the channel’s id,
platform, handle and the error.
Verify the signature
Check every request before trusting it:- Read the raw request body as text. Don’t parse and re-serialize it first.
- Compute HMAC-SHA256 of
<Postbase-Timestamp>.<raw body>with your secret, as hex, and prefix it withsha256=. - Compare it with
Postbase-Signaturein constant time. - Reject timestamps more than 5 minutes old, so a captured request can’t be replayed.
Node.js
Python
Delivery and retries
Return any2xx within 10 seconds; do slow work afterwards. Anything else
(including a timeout or a redirect) counts as a failure and is retried after
1 minute, 5 minutes, 30 minutes, 2 hours and 6 hours, then marked failed. You
can see every attempt with GET /webhooks/{id} or on the Developers page.
The same event can arrive more than once (for example if your endpoint saved it
but answered slowly). Store the event id and skip ones you’ve already handled.
Endpoints must be public https:// URLs. Private and internal addresses are
refused.