Webhooks
An accepted send only means Fabric owns the work. The terminal outcome — delivered, undelivered, failed — arrives later as a signed webhook event. Fabric delivers at least once, so your endpoint must verify the signature against the raw body, respond quickly, and treat each event idempotently.
Verify with the SDK
Section titled “Verify with the SDK”import { Fabric } from "@fabric-messaging/sdk";
const fabric = new Fabric({ apiKey: process.env.FABRIC_API_KEY! });
export async function POST(request: Request) { const payload = await request.text();
const event = fabric.webhooks.verify({ payload, signature: request.headers.get("fabric-signature") ?? undefined, secret: process.env.FABRIC_WEBHOOK_SECRET!, });
await processOnce(event.id, event); return new Response("ok", { status: 200 });}Pass the raw request text — never a parsed-and-reserialised object. Any byte change invalidates
the HMAC. verify returns a typed WebhookEvent or throws WebhookVerificationError.
EventsThe event catalog and the payload shape for each type.
SignaturesThe signing scheme, tolerance, and every verification failure code.
Retries & idempotencyDelivery states, replay of a dead delivery, and safe consumers.