Webhooks
Webhooks let you receive real-time HTTP notifications when events happen in IPAbuse — such as a report being verified, an IP's risk level changing, or a credit transaction completing.
Webhooks are available on the Pro plan and above.
Configure a webhook
- Go to Settings → Webhooks.
- Click Add Endpoint.
- Enter your HTTPS URL and choose which events to subscribe to.
- Copy the signing secret — you need it to verify payloads.
Event types
| Event | Trigger |
|---|---|
| report.created | A new abuse report is submitted |
| report.verified | A report is verified by our system |
| ip.risk_changed | An IP's risk level moves up or down a tier |
| credits.earned | You earn credits for a verified report |
| subscription.renewed | Your plan renews successfully |
| subscription.cancelled | Your plan is cancelled |
Payload shape
JSON
{
"event": "report.verified",
"timestamp": "2025-01-15T10:23:00Z",
"data": {
"reportId": "rpt_01HXXX",
"ipAddress": "1.2.3.4",
"category": "SPAM",
"creditsEarned": 10
}
}Verifying signatures
Every webhook request includes an X-IPAbuse-Signature header with a sha256=... HMAC of the raw request body. Always verify this before processing the payload:
TypeScript
import crypto from "crypto";
export function verifyWebhook(rawBody: string, signature: string, secret: string): boolean {
const expected = crypto
.createHmac("sha256", secret)
.update(rawBody, "utf8")
.digest("hex");
return crypto.timingSafeEqual(
Buffer.from(signature),
Buffer.from(`sha256=${expected}`),
);
}
// In your route handler:
// const rawBody = await req.text();
// const sig = req.headers.get("X-IPAbuse-Signature") ?? "";
// if (!verifyWebhook(rawBody, sig, process.env.WEBHOOK_SECRET!)) {
// return new Response("Forbidden", { status: 403 });
// }Delivery guarantees
- At-least-once delivery — your endpoint may receive duplicate events.
- We retry up to 5 times with exponential back-off (5 s, 30 s, 2 min, 10 min, 1 h).
- Your endpoint must respond with a 2xx status within 30 seconds.
- After 5 failed attempts the webhook is marked as failing and you are notified by email.
Next steps
- API Reference — manage webhooks via the API.
- Errors — error codes you may see in webhook payloads.