← PushPig
Webhooks
HMAC-signed, idempotent event delivery into your own systems.
Webhooks bring PushPig events into your own systems: on every relevant event
PushPig calls a URL you configure: signed, idempotent and with automatic retries.
Available events
push.sent: push delivered to at least one recipient
push.failed: no recipient reached
channel.subscribed / channel.unsubscribed
bulk.completed: bulk job finished
Signed & tamper-proof
Every request carries an X-PushPig-Signature header (HMAC-SHA256 over
"<timestamp>.<body>" with your webhook secret). That's how you verify
authenticity; the fresh timestamp protects against replay attacks.
X-PushPig-Event: push.sent
X-PushPig-Delivery: 8a4f9b21c0d3...
X-PushPig-Signature: sha256=<HMAC-SHA256("<ts>.<body>", secret)>
Reliable delivery
Failed deliveries are retried up to 5× with exponential backoff. The
X-PushPig-Delivery ID stays identical across all attempts so you can rule out double
processing (idempotency).
Full payload examples and verification code are in the
API reference.
Frequently asked questions
How do I verify a PushPig webhook signature?
Compute HMAC-SHA256 over the string made of the timestamp, a dot and the raw request body, using your webhook secret as the key. The result must match the value in the X-PushPig-Signature header, prefixed there with sha256=. Note that what is signed is not the body alone but timestamp and body together.
Which events can I subscribe to?
push.sent, push.failed, channel.subscribed, channel.unsubscribed and bulk.completed. Per webhook you choose which of them should reach you.
How often is a failed webhook retried?
Up to five times, with a growing gap: 30 seconds, 5 minutes, 30 minutes, 1 hour. Any response outside the 2xx range counts as a failure, as does a timeout, which kicks in after 8 seconds.
How do I avoid processing an event twice?
Use the X-PushPig-Delivery header, which stays identical across every retry of the same event. Store the value and discard requests carrying an ID you already processed.
What protects against replay attacks?
Every send attempt carries a fresh timestamp that is part of the signature. Reject requests whose X-PushPig-Timestamp deviates more than 300 seconds from your own clock. Genuine retries carry a new, valid timestamp and still get through.
Are webhooks included in the free plan?
No, webhooks are part of the Pro plan.
Help & API ·
Pricing ·
Contact ·
Imprint ·
Privacy