Klaviyo Webhooks
E-commerce email and SMS marketing platform. Receive events for email opens/clicks/bounces, SMS delivery, and marketing subscription changes via the Webhooks API.
Connecting Klaviyo to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Klaviyo. Then:
- 1Requires Klaviyo's Advanced Klaviyo Data Platform (KDP) add-on, or building a Klaviyo app/OAuth integration
- 2Go to Klaviyo → Advanced KDP → Data management → Webhooks, then click "Create webhook"
- 3Set the Endpoint URL to your Hookbase ingest URL and choose the Topics (events) to trigger it
- 4Set a Secret key when creating the webhook — this is what Klaviyo signs requests with
- 5Add the secret key to your Hookbase source for HMAC-SHA256 signature verification
Signature verification
Klaviyo signs its webhooks with HMAC-SHA256 (body + timestamp) in Klaviyo-Signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Klaviyo can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at The secret key set when creating the webhook (Klaviyo → Advanced KDP → Data management → Webhooks → Create webhook).
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Klaviyo event types
8 of the events people route most often. Hookbase accepts every event Klaviyo sends, whether or not it is listed here.
event:klaviyo.subscribed_to_email_marketing
A profile consented to email marketing (e.g. via a signup form)
event:klaviyo.unsubscribed_from_email_marketing
A profile unsubscribed from email marketing
event:klaviyo.opened_email
A recipient opened a marketing or flow email
event:klaviyo.clicked_email
A recipient clicked a link inside an email
event:klaviyo.bounced_email
An email soft- or hard-bounced
event:klaviyo.subscribed_to_sms_marketing
A profile consented to SMS marketing
event:klaviyo.received_sms
A recipient received an SMS from a flow or campaign
event:klaviyo.opened_push
A recipient tapped a push notification, opening the app
What a Klaviyo webhook looks like
A event:klaviyo.subscribed_to_email_marketing payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"meta": {
"klaviyo_account_id": "AbC123",
"klaviyo_webhook_id": "a8b890458b4bbfaa26d961471b83c101d6de23bd826e7e5173a15310985ec3cb",
"timestamp": "2024-01-15T10:30:00.000000+00:00",
"version": "2024-01-15"
},
"data": [
{
"external_id": "4L3cwQae2TX",
"topic": "event:klaviyo.subscribed_to_email_marketing",
"payload": {
"data": {
"type": "event",
"id": "4L3cwQae2TX",
"attributes": {
"timestamp": 1705314600,
"datetime": "2024-01-15T10:30:00+00:00",
"uuid": "58edf080-87d0-11ee-8001-895ec29a6280",
"event_properties": {
"$source": "Signup Form",
"List Name": "Newsletter"
}
},
"relationships": {
"profile": {
"data": {
"type": "profile",
"id": "01HFAD5MDRT48NN8VN7H1NB0BH"
}
},
"metric": {
"data": {
"type": "metric",
"id": "Utt3N2"
}
}
}
}
}
}
]
}Start receiving Klaviyo webhooks
Create a source, paste the URL into Klaviyo, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free