Developer Tools
LaunchDarkly Webhooks
Feature management and experimentation platform. Receive events when flags, targeting rules, or segments change — the webhook payload mirrors the account audit log entry.
Connecting LaunchDarkly to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into LaunchDarkly. Then:
- 1Go to LaunchDarkly → Organization settings (gear icon) → Integrations
- 2Search for "Webhooks" and click "Add integration"
- 3Set the URL to your Hookbase ingest URL
- 4Optionally scope the webhook with a policy filter (e.g. limit to one project, environment, or flag)
- 5Enable "Sign this webhook" to auto-generate a secret (or supply your own), then add it to your Hookbase source
Signature verification
LaunchDarkly signs its webhooks with HMAC-SHA256 (hex digest) in X-LD-Signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if LaunchDarkly can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Auto-generated or custom secret set when creating the webhook (Organization settings → Integrations → Webhooks).
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
LaunchDarkly event types
6 of the events people route most often. Hookbase accepts every event LaunchDarkly sends, whether or not it is listed here.
flag.createFlag
A new feature flag was created
flag.updateOn
A feature flag was turned on or off
flag.updateRules
A flag's targeting rules were changed
flag.updateTargets
Individual user/context targets were added to or removed from a flag
flag.updateArchived
A feature flag was archived
flag.updateTag
Tags were added to or removed from a flag
What a LaunchDarkly webhook looks like
A flag.updateOn payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"_id": "5e38bf6706121d8aaf15392a",
"_accountId": "569f514156e003339cfd3917",
"timestamp": {
"seconds": 1580777319,
"rfc3339": "2020-02-04T00:48:39Z"
},
"kind": "flag",
"name": "Demo flag",
"key": "demo-flag",
"comment": "Do it live!",
"project": {
"name": "The big project",
"key": "default",
"environment": {
"name": "Production",
"key": "production"
}
},
"member": {
"_id": "569f514183f2164430000002",
"email": "testing@launchdarkly.com",
"firstName": "Henrietta",
"lastName": "Powell"
},
"titleVerb": "turned on the flag",
"verbKind": "updateOn",
"title": {
"plainText": "Henrietta Powell turned on the flag Demo flag in 'Production'"
},
"target": {
"name": "Demo flag",
"_id": "5e38c13206121d8aaf10000c"
}
}Start receiving LaunchDarkly webhooks
Create a source, paste the URL into LaunchDarkly, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free