Infrastructure
Heroku Webhooks
Cloud application platform. Receive events for app releases, dyno state changes, and add-on updates.
Connecting Heroku to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Heroku. Then:
- 1Create a webhook via the Heroku CLI: heroku webhooks:add -a your-app
- 2Use --url flag with your Hookbase ingest URL
- 3Use --include flag to specify events (api:release, api:build, etc.)
- 4The signing secret is returned on creation — add it to your Hookbase source
Signature verification
Set the source's provider to heroku and paste the signing secret. Every request is checked before the event is stored, and anything that fails is rejected rather than quietly recorded.
- Algorithm
- HMAC-SHA256 (base64)
- Header
- Heroku-Webhook-Hmac-SHA256
- Where to find the secret
- Generated when creating the webhook subscription via Heroku API or CLI
Heroku event types
7 of the events people route most often. Hookbase accepts every event Heroku sends, whether or not it is listed here.
api:release
A new release was created
api:build
A build started or completed
api:app
An app was updated
api:dyno
A dyno state changed
api:formation
Dyno formation was changed (scaled)
api:addon
An add-on was provisioned or changed
api:domain
A custom domain was added or removed
What a Heroku webhook looks like
A api:release payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"id": "evt-abc123",
"action": "create",
"resource": "release",
"data": {
"id": "rel-def456",
"version": 42,
"description": "Deploy abc123de",
"status": "succeeded",
"app": {
"id": "app-ghi789",
"name": "my-api-prod"
},
"user": {
"email": "dev@example.com"
},
"created_at": "2024-01-15T10:30:00Z"
},
"published_at": "2024-01-15T10:30:01Z"
}Start receiving Heroku webhooks
Create a source, paste the URL into Heroku, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free