Auth & Identity
Auth0 Webhooks
Identity platform by Okta. Receive events for logins, signups, password changes, and security alerts via Log Streams.
Connecting Auth0 to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Auth0. Then:
- 1Go to Auth0 Dashboard → Monitoring → Streams
- 2Click "Create Log Stream" and select "Custom Webhook"
- 3Paste your Hookbase ingest URL
- 4Set an Authorization Token and add it to your Hookbase source
- 5Select the event categories to stream
Signature verification
Auth0 signs its webhooks with HMAC-SHA256 in Auth0-Signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Auth0 can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Auth0 Dashboard → Monitoring → Streams → Your Webhook Stream → Authorization Token.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Auth0 event types
8 of the events people route most often. Hookbase accepts every event Auth0 sends, whether or not it is listed here.
ss
Successful login
f
Failed login
sapi
API operation success
fapi
API operation failure
sce
Successful email change
scp
Successful password change
fcoa
Failed cross-origin authentication
limit_wc
Blocked IP address
What a Auth0 webhook looks like
A ss payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"log_id": "90020240115103000123456",
"data": {
"date": "2024-01-15T10:30:00.000Z",
"type": "ss",
"description": "Successful login",
"connection": "Username-Password-Authentication",
"client_id": "abc123def456",
"client_name": "My SPA",
"ip": "203.0.113.42",
"user_agent": "Mozilla/5.0...",
"user_id": "auth0|507f1f77bcf86cd799439011",
"user_name": "jane@example.com"
}
}Start receiving Auth0 webhooks
Create a source, paste the URL into Auth0, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free