Fintech
GoCardless Webhooks
Bank payment platform for Direct Debit and Open Banking collections across the UK and Europe. Receive events for payments, mandates, payouts, and subscriptions.
Connecting GoCardless to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into GoCardless. Then:
- 1Go to GoCardless Dashboard → Developers → Webhooks
- 2Click "Add endpoint" and paste your Hookbase ingest URL
- 3Copy the webhook endpoint secret shown after creation
- 4Add the secret to your Hookbase source — GoCardless signs every request with an HMAC-SHA256 hex digest of the raw body, sent in the Webhook-Signature header
- 5Verify against the raw request body only — re-serializing the parsed JSON will change the byte sequence and break verification
Signature verification
GoCardless signs its webhooks with HMAC-SHA256 (hex digest of the raw request body) in Webhook-Signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if GoCardless can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at GoCardless Dashboard → Developers → Webhooks → select your endpoint → Webhook secret.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
GoCardless event types
8 of the events people route most often. Hookbase accepts every event GoCardless sends, whether or not it is listed here.
payments.confirmed
A payment was confirmed by the customer's bank and can no longer be cancelled
payments.paid_out
A payment was included in a payout to your bank account
payments.failed
A payment failed (e.g. insufficient funds, invalid mandate)
payments.charged_back
A payment was charged back by the customer's bank
mandates.active
A Direct Debit mandate was confirmed by the bank and is ready to collect against
mandates.cancelled
A mandate was cancelled by the customer, their bank, or via the API
payouts.paid
A payout was sent to your bank account
subscriptions.cancelled
A subscription was cancelled
What a GoCardless webhook looks like
A payments.confirmed payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"events": [
{
"id": "EV123",
"created_at": "2024-01-15T10:30:00.000Z",
"resource_type": "payments",
"action": "confirmed",
"links": {
"payment": "PM123"
},
"details": {
"origin": "gocardless",
"cause": "payment_confirmed",
"description": "Payment confirmed",
"scheme": "bacs"
}
}
]
}Start receiving GoCardless webhooks
Create a source, paste the URL into GoCardless, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free