Version
WEBHOOK

member.resource_added

A subscriber gains access to a specific resource.

When this fires

Subscriby asks the resource's connector to give a subscriber access to one of the resources their subscription grants (on a connector that grants by link, a join-request invite link named after them) and writes the grant to the access ledger. Each resource grant emits its own event. The event marks the grant, not the subscriber's arrival: they may not have opened the link yet; the ledger row named by grant_id moves from pending to granted when they do. A manual perk arrives here too, once the creator completes its task (creator_task.completed precedes it).

Caveats

  • Ordering against the join event is not guaranteed: the dispatcher is queued before member.joined is emitted on the access-code path, and paid joins emit no member.* join event at all. Treat resource events as independent.
  • A manual perk emits this event only when its creator task is completed, never at purchase; until then the member's grant is pending and creator_task.opened is what fired.

Related events

  • member.resource_removed: paired transition.
  • member.joined, member.trial_joined: typical predecessors.

Ability to subscribe

A token needs this to subscribe an endpoint to the event.

Header Parameters

SB-Signature*string

t=<unix seconds>,v1=<hex>: the HMAC-SHA256 of "<t>.<raw body>" under the endpoint's secret. Verify it before acting, and refuse a t more than 300 seconds from now. During a secret rotation a v0= signature under the previous secret may precede v1=.

SB-Event-Id*string

The event's ULID, bare. The envelope's id is the same ULID prefixed evt_, so strip the prefix before comparing. Deduplicate on it: a retry carries the same id.

SB-Event-Name*string

The event name, the same as the envelope's type.

Content-Type*string

Always application/json.

User-Agent*string

Always Subscriby-Webhooks/1.0.

Payload

JSONWhat Subscriby posts to your endpoint

The signed JSON envelope posted to your endpoint.

The envelope every event is delivered in.

Responses

2XXAny success status

Your endpoint acknowledged the delivery. Any 2xx status within 30 seconds marks it delivered; the response body is ignored.

defaultAny other status

Any other status, a connection failure, or no answer within 30 seconds counts as a failed attempt. The delivery is retried 8 times, after 10 seconds, 30 seconds, 2 minutes, 10 minutes, 1 hour, 6 hours, 1 day, 3 days; the last failure dead-letters it, and it can be retried from the dashboard or POST /v1/webhook-deliveries/{delivery}/retry. After 20 consecutive failures the endpoint is paused until it is resumed.

How is this guide?

Last updated on