Skip to content

basalt / subscriptions/src / billingWebhookRoute

Function: billingWebhookRoute() ​

> billingWebhookRoute(gateway, options?): BasaltRoute

Defined in: subscriptions/src/plugin.ts:339

Webhook endpoint: POST /billing/webhook — signature verified by the gateway driver over the raw request bytes, processing idempotent by event id. Returns 200 with { received, duplicate } so gateways stop retrying.

The body is declared with rawBody() from @basaltkit/http, so every adapter (Fastify, Express, Hono) hands the handler the exact bytes that arrived, untouched and unparsed, after the pipeline's guards have run. That is not a nicety: Stripe, Paddle, Lemon Squeezy and GitHub all sign the octets, and JSON.stringify of a parsed object is a different message — different whitespace, different key order, 1.50 re-printed as 1.5. This route used to fall back to exactly that when a raw body was absent, which it always was, so every genuine delivery failed verification. There is no fallback any more: no bytes means a refusal, never a reconstruction.

Parameters ​

gateway ​

BillingGateway

options? ​

BillingWebhookRouteOptions = {}

Returns ​

BasaltRoute

Released under the MIT License.