LinkRunway saves outgoing events in a transactional outbox. A worker sends them to your HTTPS endpoint with a timestamp, delivery ID, and HMAC signature. Your receiver verifies the signature and deduplicates before processing.
Before you begin.
- A public HTTPS receiver on port 443
- A durable queue or database in your service
- Workspace owner access
Choose what your system needs.
Open Event webhooks → Add endpoint. Enter the public HTTPS URL and select event types. Save the one-time signing secret in the receiving service. Private IP addresses and redirects are not supported.
Authenticate the exact bytes.
Read the unmodified body before JSON parsing. Verify the timestamp and HMAC in constant time. The signature covers the timestamp, a period, and the raw body.
import { createHmac, timingSafeEqual } from 'node:crypto';
export function verify(rawBody, headers, secret) {
const time = headers['x-linkrunway-timestamp'];
const signature = headers['x-linkrunway-signature'];
if (!/^\d+$/.test(time ?? '') ||
Math.abs(Date.now() / 1000 - Number(time)) > 300)
throw new Error('Expired timestamp');
if (!/^v1=[a-f0-9]{64}$/.test(signature ?? ''))
throw new Error('Invalid signature');
const expected = createHmac('sha256', secret)
.update(time + '.').update(rawBody).digest();
const actual = Buffer.from(signature.slice(3), 'hex');
if (!timingSafeEqual(expected, actual))
throw new Error('Invalid signature');
}Accept once. Process reliably.
After verification, persist the x-linkrunway-id and event in your own transaction or queue, then return a 2xx response. Use a unique delivery-ID constraint and return success for previously accepted IDs.
- Check the event’s verified flag before treating it as trusted revenue.
- Do not use unverified client identity as canonical customer identity.
- Apply downstream business effects idempotently as well.
Keep delivery in view.
The console shows delivery status, attempts, and the last response. Network and server failures retry with backoff. Fix configuration or validation errors before retrying a terminal failure. Rotating the endpoint secret invalidates the previous secret immediately.
Find the missing connection.
The signature never matches
Make sure middleware has not changed whitespace or reserialized the JSON. Use the exact raw request bytes.
The same event arrives again
This is expected with at-least-once delivery. Deduplicate the delivery ID before applying side effects.
Delivery stops after a 400 response
Most 4xx errors are terminal. Fix your receiver, then use Retry in Event webhooks.
Reviewed October 10, 2026 · LinkRunway documentation
