Auth & Identity
Supabase Auth Hooks Webhooks
Synchronous hooks fired during sign-up, sign-in and token issuance — separate from Database Webhooks, and signed (Standard Webhooks spec) where Database Webhooks are not.
Connecting Supabase Auth Hooks to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Supabase Auth Hooks. Then:
- 1Go to Supabase Dashboard → Authentication → Hooks
- 2Choose a hook (e.g. "Custom Access Token", "Send Email") and set it to "HTTPS"
- 3Paste your Hookbase ingest URL and copy the generated secret
- 4Select "Supabase Auth Hooks" — not "Supabase" — as the provider on your Hookbase source, since the secret is prefixed "v1,whsec_" rather than the plain Standard Webhooks "whsec_"
Signature verification
Set the source's provider to supabase-auth-hooks and paste the signing secret. Every request is checked before the event is stored, and anything that fails is rejected rather than quietly recorded.
- Algorithm
- HMAC-SHA256 (Standard Webhooks)
- Header
- webhook-signature
- Where to find the secret
- Supabase Dashboard → Authentication → Hooks → your hook → Secret (format: v1,whsec_<base64-secret>)
Supabase Auth Hooks event types
6 of the events people route most often. Hookbase accepts every event Supabase Auth Hooks sends, whether or not it is listed here.
before-user-created
Fires when a user is created
custom-access-token
Fires each time a new JWT is created, to add or edit its claims
send-sms
Fires each time an SMS is sent, to use a custom SMS provider
send-email
Fires each time an email is sent, to use a custom email provider
mfa-verification-attempt
Fires each time a user tries to verify an MFA factor
password-verification-attempt
Fires each time a user tries to sign in with a password
What a Supabase Auth Hooks webhook looks like
A custom-access-token payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"user_id": "8ccaa7af-909f-44e7-84cb-67cdccb56be6",
"claims": {
"aud": "authenticated",
"exp": 1715690221,
"iat": 1715686621,
"sub": "8ccaa7af-909f-44e7-84cb-67cdccb56be6",
"email": "",
"phone": "",
"app_metadata": {},
"user_metadata": {},
"role": "authenticated",
"aal": "aal1",
"amr": [
{
"method": "anonymous",
"timestamp": 1715686621
}
],
"session_id": "4b938a09-5372-4177-a314-cfa292099ea2",
"is_anonymous": true
},
"authentication_method": "anonymous"
}Start receiving Supabase Auth Hooks webhooks
Create a source, paste the URL into Supabase Auth Hooks, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free