Version
WEBHOOK

partner.referral_signed_up

A new creator account arrived through the partner's link, typed the partner's code at sign-up or came in through the platform bot's deep link, and the referral was recorded.

When this fires

Someone registered a new creator account with the partner's cookie on their browser (set by the partner link for 60 days), typed the partner's code on the sign-up page with no cookie present, or started the platform bot through the partner's deep link, and every capture rule passed: the partner is active, the account is new, it is not the partner's own, and it holds no referral yet.

First touch wins. An account carries one partner referral for life. The cookie beats a typed code, a second code from anyone is refused, and the referral stays open for 180 days: a first paid Starter or Growth invoice inside that window converts it, and one that sees none expires quietly.

Caveats

  • A refused capture emits nothing, whatever the reason: a self-referral, a suspended partner, an unknown code, an account that already carries a referral.
  • A held sign-up still emits this event. A sign-up that looks like the partner themselves (their own network, an alias of their email, or one link bringing too many sign-ups in a day) is recorded and held for review from the start; it emits partner.referral_signed_up like any other, converts and earns silently, and the hold shows nowhere in this family until it is decided.
  • Expiry emits nothing either. A referral past expires_at is closed by a nightly sweep and announced nowhere; schedule against expires_at if you need the moment.
  • The friend's discount is not in this event. The referred creator's 20% off their first three months rides on their own account and shows on their invoices; the partner's commission is taken from the discounted total.

Related events

  • partner.referral_converted: the first paid invoice inside the window.

Ability to subscribe

A token needs this to subscribe an endpoint to the event.

Header Parameters

SB-Signature*string

t=<unix seconds>,v1=<hex>: the HMAC-SHA256 of "<t>.<raw body>" under the endpoint's secret. Verify it before acting, and refuse a t more than 300 seconds from now. During a secret rotation a v0= signature under the previous secret may precede v1=.

SB-Event-Id*string

The event's ULID, bare. The envelope's id is the same ULID prefixed evt_, so strip the prefix before comparing. Deduplicate on it: a retry carries the same id.

SB-Event-Name*string

The event name, the same as the envelope's type.

Content-Type*string

Always application/json.

User-Agent*string

Always Subscriby-Webhooks/1.0.

Payload

JSONWhat Subscriby posts to your endpoint

The signed JSON envelope posted to your endpoint.

The envelope every event is delivered in.

Responses

2XXAny success status

Your endpoint acknowledged the delivery. Any 2xx status within 30 seconds marks it delivered; the response body is ignored.

defaultAny other status

Any other status, a connection failure, or no answer within 30 seconds counts as a failed attempt. The delivery is retried 8 times, after 10 seconds, 30 seconds, 2 minutes, 10 minutes, 1 hour, 6 hours, 1 day, 3 days; the last failure dead-letters it, and it can be retried from the dashboard or POST /v1/webhook-deliveries/{delivery}/retry. After 20 consecutive failures the endpoint is paused until it is resumed.

How is this guide?

Last updated on