Overview
Better Data supports two directions of webhook traffic:- Inbound webhooks — external platforms (Stripe, Shopify) notify Better Data of events
- Outbound webhooks — Better Data notifies your systems when domain events occur (planned)
Outbound webhook configuration is in active development.
Contact support@betterdata.co to join the early access list.
Inbound Webhooks
Stripe Billing POST /webhooks/stripe
Status: Live (handler: apps/cco-api/app/webhooks/stripe/route.ts in bd-forge-main)
Handles Stripe subscription and invoice lifecycle events.
Used for billing updates, entitlement recomputation, and audit logging.
Verification
All requests are verified using the stripe-signature header.
Requests without a valid signature are rejected with 400.
Handled events
Setup
Configure your Stripe webhook to point to:
STRIPE_WEBHOOK_SECRET environment variable to your Stripe signing secret.
Square (catalog / inventory webhooks)
Status: Route exists; implementation not live —POST /api/webhooks/square (apps/cco-api/app/api/webhooks/square/route.ts) currently returns 501 with a JSON error body indicating SquareWebhookHandler / related models are incomplete (see inline comment in that file).
Implementation detail pending verification: when Shopify or other provider-specific inbound routes are added under apps/cco-api, list them here from the same codebase scan (do not assume parity with this Square stub).
Contact support@betterdata.co if you need a timeline for Square inbound processing beyond the stub response.
Outbound Webhooks (Planned)
Better Data will send outbound webhook notifications when key domain events occur in your loops. Planned event coverage
Configuration
Webhook endpoints will be configurable at:
apps.betterdata.co/settings/webhooks
Delivery will include:
- HMAC signature verification
- Retry with exponential backoff
- Delivery log with per-event status
Outbound webhooks are in active development.
Join the early access list: support@betterdata.co
Federation Webhooks (Planned)
Commerce Gateway merchants can configure awebhookUrl to receive
federation events. Delivery is not yet implemented.
Webhook Security
All inbound webhooks verify request authenticity before processing. Stripe:stripe-signature HMAC verification using your webhook signing secret.
Future inbound sources: HMAC-SHA256 signature in x-betterdata-signature header
(implementation in progress).
Never expose webhook secrets in client-side code or public repositories.