Version
WEBHOOK

referral.captured

A member arrived through an affiliate's link or typed their code, and the touch was recorded.

When this fires

A member opened the portal or a connector's deep link carrying an affiliate's code, or typed the code at checkout, and every capture rule passed: the programme is live, the code belongs to an approved affiliate of this project, the member is not the affiliate, holds no referral row yet, and has never settled a payment on the project.

First touch wins. A member carries one referral for life on a project. A second code, from anyone, is refused and emits nothing. The touch lasts the attribution window (thirty days by default); a first payment inside it converts the touch, and a touch that sees none expires quietly.

Caveats

  • A refused capture emits nothing, whatever the reason: a self-referral, a suspended code, a paused programme, a member who already paid.
  • Expiry emits nothing either. A touch past expires_at is closed by a nightly sweep and announced nowhere; schedule against expires_at if you need the moment.

Related events

  • referral.converted: the first payment inside the window.

Ability to subscribe

A token needs this to subscribe an endpoint to the event.

Header Parameters

SB-Signature*string

t=<unix seconds>,v1=<hex>: the HMAC-SHA256 of "<t>.<raw body>" under the endpoint's secret. Verify it before acting, and refuse a t more than 300 seconds from now. During a secret rotation a v0= signature under the previous secret may precede v1=.

SB-Event-Id*string

The event's ULID, bare. The envelope's id is the same ULID prefixed evt_, so strip the prefix before comparing. Deduplicate on it: a retry carries the same id.

SB-Event-Name*string

The event name, the same as the envelope's type.

Content-Type*string

Always application/json.

User-Agent*string

Always Subscriby-Webhooks/1.0.

Payload

JSONWhat Subscriby posts to your endpoint

The signed JSON envelope posted to your endpoint.

The envelope every event is delivered in.

Responses

2XXAny success status

Your endpoint acknowledged the delivery. Any 2xx status within 30 seconds marks it delivered; the response body is ignored.

defaultAny other status

Any other status, a connection failure, or no answer within 30 seconds counts as a failed attempt. The delivery is retried 8 times, after 10 seconds, 30 seconds, 2 minutes, 10 minutes, 1 hour, 6 hours, 1 day, 3 days; the last failure dead-letters it, and it can be retried from the dashboard or POST /v1/webhook-deliveries/{delivery}/retry. After 20 consecutive failures the endpoint is paused until it is resumed.

How is this guide?

Last updated on