Request headers
Request body
string
The trigger that fired:
on_create, on_update, or on_delete.string
The resource name (e.g.
order, contact).string
Unique event UUID created by Exo for this trigger occurrence.
string
Unique delivery UUID for this specific webhook attempt.
object
The transformed record data, as returned by the resource’s
transform method. Date fields are formatted as ISO-8601 strings.string
UTC timestamp of when the event was processed, in microsecond precision:
2026-03-28T14:30:00.123456Z.Example payload
Signature verification
TheX-Exo-Signature header contains an HMAC-SHA256 hash of the raw JSON body, computed using the subscription’s secret as the key.
To verify:
- Read the raw request body (before parsing)
- Compute
sha256=+ hex-encoded HMAC-SHA256 of the body using your subscription’s secret - Compare with the
X-Exo-Signatureheader using a constant-time comparison
Delivery behavior
- Webhooks are delivered via Laravel’s queue system as background jobs
- Each delivery timeout is controlled by
exo.webhook.timeout(30 seconds by default) - If your endpoint returns a non-2xx status or times out, Exo retries based on
max_attemptsandbackoffconfiguration (or per-Resource webhook overrides) - Admins receive webhooks for all records; regular users only receive webhooks for records they own
- Inactive subscriptions (
is_active = false) are skipped during delivery