Skip to main content

Module dodo

Module dodo 

Source
Expand description

Dodo Payments: webhook signatures (Standard Webhooks), the subscription envelope, and the two API calls the app makes (checkout and customer portal).

Field names in the webhook payload follow Dodo’s documentation. They are read leniently (everything optional, unknown fields ignored) and should be confirmed against payloads from Dodo’s live webhook deliveries before launch.

Structs§

DodoEvent
NotAnObject
The body wasn’t a JSON object.
Subscription

Enums§

DodoError
SigError

Constants§

MIN_KEY_BYTES
The shortest webhook key accepted. HMAC takes a key of any length, an empty one included, so without a floor a whsec_ secret with nothing after it would “verify” forgeries.
TOLERANCE_SECS
How far a webhook’s timestamp may be from now, either way.

Functions§

create_checkout
Starts a hosted checkout for product_id; returns the page to send the customer to.
create_portal_session
Opens a customer-portal session; returns the link to send the customer to.
key
The HMAC key behind a whsec_<base64> secret.
parse_event
Reads a verified webhook body. Fails only when it isn’t a JSON object; every field inside is optional, and one of the wrong type counts as absent.
sign
The webhook-signature value for a body: what Dodo sends, and what tests send.
verify
Checks a webhook the Standard Webhooks way: webhook-id, webhook-timestamp (unix seconds, within five minutes of now) and webhook-signature (v1,<base64 HMAC-SHA256 of "{id}.{timestamp}.{body}">, several separated by spaces; one valid is enough). Signatures are compared in constant time.