Skip to content

Webhooks

An accepted send only means Fabric owns the work. The terminal outcome — delivered, undelivered, failed — arrives later as a signed webhook event. Fabric delivers at least once, so your endpoint must verify the signature against the raw body, respond quickly, and treat each event idempotently.

import { Fabric } from "@fabric-messaging/sdk";
const fabric = new Fabric({ apiKey: process.env.FABRIC_API_KEY! });
export async function POST(request: Request) {
const payload = await request.text();
const event = fabric.webhooks.verify({
payload,
signature: request.headers.get("fabric-signature") ?? undefined,
secret: process.env.FABRIC_WEBHOOK_SECRET!,
});
await processOnce(event.id, event);
return new Response("ok", { status: 200 });
}

Pass the raw request text — never a parsed-and-reserialised object. Any byte change invalidates the HMAC. verify returns a typed WebhookEvent or throws WebhookVerificationError.