Payments
Braintree Webhooks
PayPal-owned payment platform. Receive events for transactions, subscriptions, disputes, and disbursements.
Connecting Braintree to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Braintree. Then:
- 1Go to Braintree Control Panel → Settings → Webhooks
- 2Click "Create New Webhook" and paste your Hookbase ingest URL
- 3Select the notification types to receive
- 4Braintree uses key-pair signing — note the public key for verification
Signature verification
Braintree signs its webhooks with SHA1 with public/private key pair in bt-signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Braintree can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Braintree Control Panel → Settings → API → Webhooks → Public Key.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Braintree event types
9 of the events people route most often. Hookbase accepts every event Braintree sends, whether or not it is listed here.
subscription_charged_successfully
A subscription was successfully charged
subscription_charged_unsuccessfully
A subscription charge failed
subscription_canceled
A subscription was canceled
subscription_went_past_due
A subscription went past due
transaction_settled
A transaction was settled
transaction_settlement_declined
A transaction settlement was declined
dispute_opened
A dispute was opened
dispute_lost
A dispute was lost
disbursement
Funds were disbursed to the merchant
What a Braintree webhook looks like
A subscription_charged_successfully payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"kind": "subscription_charged_successfully",
"timestamp": "2024-01-15T10:30:00Z",
"subject": {
"subscription": {
"id": "sub_abc123",
"plan_id": "premium_monthly",
"status": "Active",
"price": "29.99",
"transactions": [
{
"id": "txn_def456",
"amount": "29.99",
"status": "settled"
}
]
}
}
}Start receiving Braintree webhooks
Create a source, paste the URL into Braintree, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free