basalt / subscriptions/src / billingWebhookRoute
Function: billingWebhookRoute()
> billingWebhookRoute(gateway, options?): BasaltRoute
Defined in: subscriptions/src/plugin.ts:339
Webhook endpoint: POST /billing/webhook — signature verified by the gateway driver over the raw request bytes, processing idempotent by event id. Returns 200 with { received, duplicate } so gateways stop retrying.
The body is declared with rawBody() from @basaltkit/http, so every adapter (Fastify, Express, Hono) hands the handler the exact bytes that arrived, untouched and unparsed, after the pipeline's guards have run. That is not a nicety: Stripe, Paddle, Lemon Squeezy and GitHub all sign the octets, and JSON.stringify of a parsed object is a different message — different whitespace, different key order, 1.50 re-printed as 1.5. This route used to fall back to exactly that when a raw body was absent, which it always was, so every genuine delivery failed verification. There is no fallback any more: no bytes means a refusal, never a reconstruction.
Parameters
gateway
options?
BillingWebhookRouteOptions = {}