Skip to main content
This feature is only available in the Pro or Enterprise plans.

About webhooks

Webhooks enable real-time event subscriptions within your Hanko project, automatically delivering event data to your server whenever authentication events occur. This facilitates user data synchronization and custom workflow automation. Create webhooks by specifying a callback URL and selecting events to monitor. When subscribed events occur, Hanko sends HTTP POST requests with event data to your specified endpoint. Your application can then process this data through a publicly accessible HTTPS endpoint.

High level overview of creating webhooks and handling webhook deliveries

Creating webhooks

Set up webhooks through these steps:
1

Access webhook settings

Log in to Hanko Cloud Console, select your organization and project, then navigate to Settings > Webhooks.
2

Configure your webhook

Click Create webhook, enter your callback URL, and select events for subscription. Review Events for complete event type information.
You can implement either a single webhook endpoint handling multiple events or separate webhooks for specific event types, depending on your architecture preferences.

Handling webhook deliveries

Process webhook deliveries through these steps:
1

Create callback endpoint

Implement a publicly accessible HTTP POST endpoint at your configured callback URL to receive webhook deliveries.
2

Parse webhook payload

Extract the webhook event payload containing event information and JWT-encoded event data.
3

Validate payload authenticity

Verify JWT signatures using your tenant’s .well-known endpoint to ensure deliveries originate from Hanko and remain uncompromised.
4

Decode JWT token

Parse the JWT to extract event data from the token payload. Event data structures vary by event type - see Event types and token payloads.
5

Process event data

Handle the extracted event data according to your application’s specific requirements.
This example uses express and the jose package to parse and verify JWTs.
The example assumes usage of a single HTTP endpoint for all event types but you could just as well configure multiple webhooks and use multiple HTTP endpoints.
Your server must return the complete certificate chain otherwise the request will fail.

Editing and removing webhooks

Manage existing webhooks through these steps:
1

Access webhook settings

Log in to Hanko Cloud, select your organization and project, then navigate to Settings > Webhooks.
2

Modify or delete webhooks

Find your webhook and click the three dots (...). Choose Edit to modify the callback URL or event subscriptions, or Delete to remove the webhook completely.

Events

Hanko offers various event types for subscription. Each event type determines the structure and content of the payload delivered to your callback URL.

Event payload

The structure of the event payload is the same across all event types. It contains the event type and the event data in the form of a JSON Web Token (JWT).
user.create
string
The JWT that contains the actual webhook event data. It is a JSON Web Signature (JWS). Webhook recipients should verify the signature to ensure that the webhook deliveries were sent by Hanko and have not been tampered with.
string
The event that triggered this webhook

Event types and token payloads

Events are structured hierarchically with some events subsuming the occurrence of multiple (“sub”)-events. These types of events do not actually appear as the value for the event property in the webhook event payload. Subscribing to these types of events when creating a webhook is a convenient way to group certain event types and allows you to structure your callback endpoints around these groups. A webhook’s event data is encoded as a JWT in the webhook’s callback request body. You need to parse the token to access the token’s payload which contains the actual event data (see Handling webhook deliveries for an example).

user

Subscribing to this event implies subscription to the following events: user.create, user.delete, user.login, user.update.custom_claims, user.udpate.email.create, user.update.email.delete, user.update.email.primary, user.update.password.update user.update.username.create, user.update.username.delete, user.update.username.update

user.create

This event is triggered when a new user is created.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.delete

This event is triggered when a user is deleted.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.login

This event is triggered when a user logs in.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.update

Subscribing to this event implies subscription to the following events: user.update.custom_claims, user.udpate.email.create, user.update.email.delete, user.update.email.primary, user.update.password.update user.update.username.create, user.update.username.delete, user.update.username.update

user.update.custom_claims

This event is triggered when the value of a mapped custom claim changes for a user.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.update.email

Subscribing to this event implies subscription to the following events: user.udpate.email.create, user.update.email.delete, user.update.email.primary

user.update.email.create

This event is triggered when an email is created for a user.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.update.email.delete

This event is triggered when a user’s email is deleted.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.update.email.primary

This event is triggered when a user’s email is set as the primary email.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.update.password.update

This event is triggered when a user updates their password through the profile.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.update.username

Subscribing to this event implies subscription to the following events: user.update.username.create, user.update.username.delete, user.update.username.update

user.update.username.create

This event is triggered when a username is created for a user.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.update.username.delete

This event is triggered when a user’s username is deleted.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

user.update.username.update

This event is triggered when a user’s username is updated.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

session

Subscribing to this event implies subscription to the following events: session.create.flow, session.create.admin, session.delete.explicit.logout, session.delete.explicit.revoke, session.delete.admin.revoke, session.delete.passive.expire, session.delete.passive.limit

session.create

Subscribing to this event implies subscription to the following events: session.create.flow, session.create.admin

session.create.flow

This event is triggered when a session is created through the login, registration, third-party, or token exchange flow, i.e. whenever a user authenticates.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

session.create.admin

This event is triggered when a session is created through the admin API.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

session.delete

Subscribing to this event implies subscription to the following events: session.delete.explicit.logout, session.delete.explicit.revoke, session.delete.admin.revoke, session.delete.passive.expire, session.delete.passive.limit

session.delete.explicit

Subscribing to this event implies subscription to the following events: session.delete.explicit.logout, session.delete.explicit.revoke This event group covers session deletions that were deliberately initiated by the session owner, as opposed to deletions initiated by an admin (see session.delete.admin) or triggered automatically by the system (see session.delete.passive).

session.delete.explicit.logout

This event is triggered when a user logs out.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

session.delete.explicit.revoke

This event is triggered when a user revokes one of their own other active sessions, e.g. from the profile page.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

session.delete.admin

Subscribing to this event implies subscription to the following events: session.delete.admin.revoke This event group covers session deletions initiated by an admin, as opposed to deletions initiated by the session owner (see session.delete.explicit) or triggered automatically by the system (see session.delete.passive).

session.delete.admin.revoke

This event is triggered when a session is revoked through the admin API.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

session.delete.passive

Subscribing to this event implies subscription to the following events: session.delete.passive.expire, session.delete.passive.limit This event group covers session deletions that are triggered automatically by the system rather than deliberately by a user or admin.
Because these events fire as a side effect of ordinary, high-frequency traffic (session validation checks, logins), they occur far more often than session.delete.explicit or session.delete.admin events. Subscribe to the specific leaf events below rather than to session.delete or session as a whole if you only care about deliberate session terminations.

session.delete.passive.expire

This event is triggered when a session is automatically deleted after exceeding the configured idle timeout.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

session.delete.passive.limit

This event is triggered when a session is automatically deleted because the user exceeded the configured maximum number of concurrent sessions, evicting their oldest session.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"

email.send

This event is triggered when an email is sent. Subscribe to this event if you want to send customized emails instead of emails based on built-in templates. See Custom Emails for more information.
string[]
The recipients the token is intended for
object
string
The event that triggered the webhook containing this data
number
The expiration date of the token
number
The time at which the token was issued
string
default:"hanko webhooks"