access_code.expired

A code passes its expiry without redemption.

Ability to subscribeproject-access-code:view

When this fires

An access code passes its expiry without being redeemed. The placeholder subscription row holding it is hard-deleted immediately after this event is emitted.

The code string itself is not included on this event; only access_code.redeemed carries access_code. The placeholder row referenced by subscription_id is hard-deleted immediately after this event is emitted, so it will not resolve through the API.

Caveats

  • Expiry is detected by a sweep that runs every five minutes, so created_at trails expired_at by up to five minutes plus queue latency.
  • Large batches may produce a sustained burst of access_code.expired events when the batch hits its expiry. Plan capacity accordingly.
  • Codes that were already redeemed do not produce this event regardless of the batch's expires_at.

Related events

  • access_code.redeemed: alternative outcome.
  • access_code.generated: predecessor (batch-level).

Header Parameters

SB-Signature*string

t=<unix seconds>,v1=<hex>: the HMAC-SHA256 of "<t>.<raw body>" under the endpoint's secret. Verify it before acting, and refuse a t more than 300 seconds from now. During a secret rotation a v0= signature under the previous secret may precede v1=.

SB-Event-Id*string

The event's ULID, bare. The envelope's id is the same ULID prefixed evt_, so strip the prefix before comparing. Deduplicate on it: a retry carries the same id.

SB-Event-Name*string

The event name, the same as the envelope's type.

Content-Type*string

Always application/json.

User-Agent*string

Always Subscriby-Webhooks/1.0.

Request Body

application/json

The signed JSON envelope posted to your endpoint.

TypeScript Definitions

Use the request body type in TypeScript.

The envelope every event is delivered in.

Response Body

Example Requests

POST/access_code.expired

How is this guide?