Auth & Identity
Stytch Webhooks
Authentication infrastructure. Receive events for user creation, authentication, sessions, and MFA.
Connecting Stytch to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Stytch. Then:
- 1Go to Stytch Dashboard → Webhooks
- 2Click "Create Webhook" and paste your Hookbase ingest URL
- 3Copy the signing secret and add it to your Hookbase source
- 4Select the events you want to subscribe to
Signature verification
Stytch signs its webhooks with HMAC-SHA256 in Stytch-Signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Stytch can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Stytch Dashboard → Webhooks → Signing secret.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Stytch event types
7 of the events people route most often. Hookbase accepts every event Stytch sends, whether or not it is listed here.
user.created
A new user was created
user.updated
A user was updated
user.deleted
A user was deleted
session.created
A session was created
session.revoked
A session was revoked
magic_link.authenticated
A magic link was authenticated
otp.authenticated
An OTP was authenticated
What a Stytch webhook looks like
A user.created payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"type": "user.created",
"created_at": "2024-01-15T10:30:00Z",
"data": {
"user_id": "user-live-abc123",
"emails": [
{
"email_id": "email-xyz789",
"email": "jane@example.com",
"verified": true
}
],
"phone_numbers": [],
"name": {
"first_name": "Jane",
"last_name": "Developer"
},
"created_at": "2024-01-15T10:30:00Z",
"status": "active"
}
}Start receiving Stytch webhooks
Create a source, paste the URL into Stytch, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free