Consume affiliate webhooks
Validate the destination and verify signed event bodies before processing them.
On this page
What you need
A permitted public HTTPS endpoint you control and app integration permissions. Validation sends a real connection test to the entered endpoint.
Steps
- Open Affiliate Developers and choose the intended app, destination kind and event types. Use a public HTTPS webhook or a Slack incoming webhook for Slack kind.
- Prepare the signing secret where prompted and keep it private. Configure your receiver, then validate the exact current destination/event configuration.
- The connection test must return 2xx. Save the validated configuration before the validation receipt expires. An edited URL/event selection needs fresh validation.
- For webhook kind, verify
X-HeyCrust-TimestampandX-HeyCrust-Signatureover the raw body before parsing or acting. Computev1=plus hex HMAC-SHA256 of<timestamp>.<raw body>using the signing secret. Accept a ten-digit epoch timestamp within five minutes; compare signatures safely. - Deduplicate event IDs, persist processing state and return 2xx only when your receiver accepts the event. Review attempts/errors in the delivery controls; request a retry for a corrected dead/retry delivery when appropriate.
- Revalidate updates using the current signing secret; when replacing/revoking a destination, update your receiver and revoke the obsolete subscription deliberately.
Expected result
A validated active destination and observable delivery attempts. A saved destination is not a guarantee that every later request reaches or is processed by your receiver.
Event envelope and catalog
The connection test has id, schemaVersion: 1, type: "connection.test", ISO occurredAt and data. Real deliveries follow the versioned envelope; use the event type and identifiers to load the current authorized record when needed rather than guessing a richer payload.
Event subscriptions include join request/join, referral/request, payment request, membership and terms changes, referral dispute/reassignment, commission updates/payable/bonus/refund, payout review, payment report/confirmation/dispute/resolution/reminders, tracking health and listing moderation. The exact event names below are generated from the current contract.
Troubleshooting
Redirect responses are terminal. Most 4xx failures are terminal except 408/425/429; network/server/transient errors retry, up to eight attempts. Delay grows from one minute with a one-day cap. Fix the endpoint/signature/error before requesting manual retry. Slack URL/signing behavior differs from ordinary webhooks.
Supported event names
join-requestjoinreferralreferral-requestpayment-requestmembership.provisionedmembership.rejectedmembership.suspendedmembership.archivedmembership.terms_updatedmembership.terms_proposedmembership.terms_acceptedprogram.terms_changedprogram.eligibility_changedreferral.rejectreferral.disputereferral.reassignedcommission.updatedcommission.payablecommission.bonuscommission.refundedpayout.approvedpayout.rejectedpayment.reportedpayment.confirmedpayment.disputedpayment.resolvedpayment.reminderpayment.confirmation_remindertracking.health_changedlisting.submittedlisting.moderated