Payments
PayPal Webhooks
Global payments platform. Receive events for payments, disputes, subscriptions, and payouts.
Connecting PayPal to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into PayPal. Then:
- 1Go to PayPal Developer Dashboard → My Apps & Credentials
- 2Select your app and navigate to Webhooks
- 3Click "Add Webhook" and paste your Hookbase ingest URL
- 4Select the event types you want to receive
- 5Note the Webhook ID for signature verification
Signature verification
PayPal signs its webhooks with SHA256withRSA in PAYPAL-TRANSMISSION-SIG, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if PayPal can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at PayPal Developer Dashboard → My Apps & Credentials → Webhooks → Webhook ID.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
PayPal event types
8 of the events people route most often. Hookbase accepts every event PayPal sends, whether or not it is listed here.
PAYMENT.CAPTURE.COMPLETED
A payment capture was completed
PAYMENT.CAPTURE.DENIED
A payment capture was denied
PAYMENT.CAPTURE.REFUNDED
A captured payment was refunded
CHECKOUT.ORDER.APPROVED
A checkout order was approved by the buyer
BILLING.SUBSCRIPTION.CREATED
A billing subscription was created
BILLING.SUBSCRIPTION.CANCELLED
A billing subscription was cancelled
CUSTOMER.DISPUTE.CREATED
A customer dispute was created
PAYMENT.PAYOUTS-ITEM.SUCCEEDED
A payout item succeeded
What a PayPal webhook looks like
A PAYMENT.CAPTURE.COMPLETED payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"id": "WH-1234567890",
"event_type": "PAYMENT.CAPTURE.COMPLETED",
"resource_type": "capture",
"resource": {
"id": "CAP-1234567890",
"status": "COMPLETED",
"amount": {
"currency_code": "USD",
"value": "50.00"
},
"create_time": "2024-01-15T10:30:00Z"
},
"create_time": "2024-01-15T10:30:01Z"
}Start receiving PayPal webhooks
Create a source, paste the URL into PayPal, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free