Expand description
Dodo Payments: webhook signatures (Standard Webhooks), the subscription envelope, and the two API calls the app makes (checkout and customer portal).
Field names in the webhook payload follow Dodo’s documentation. They are read leniently (everything optional, unknown fields ignored) and should be confirmed against payloads from Dodo’s live webhook deliveries before launch.
Structs§
- Dodo
Event - NotAn
Object - The body wasn’t a JSON object.
- Subscription
Enums§
Constants§
- MIN_
KEY_ BYTES - The shortest webhook key accepted. HMAC takes a key of any length, an empty one included,
so without a floor a
whsec_secret with nothing after it would “verify” forgeries. - TOLERANCE_
SECS - How far a webhook’s timestamp may be from now, either way.
Functions§
- create_
checkout - Starts a hosted checkout for
product_id; returns the page to send the customer to. - create_
portal_ session - Opens a customer-portal session; returns the link to send the customer to.
- key
- The HMAC key behind a
whsec_<base64>secret. - parse_
event - Reads a verified webhook body. Fails only when it isn’t a JSON object; every field inside is optional, and one of the wrong type counts as absent.
- sign
- The
webhook-signaturevalue for a body: what Dodo sends, and what tests send. - verify
- Checks a webhook the Standard Webhooks way:
webhook-id,webhook-timestamp(unix seconds, within five minutes ofnow) andwebhook-signature(v1,<base64 HMAC-SHA256 of "{id}.{timestamp}.{body}">, several separated by spaces; one valid is enough). Signatures are compared in constant time.