Receive webhooks
1. Add an endpoint
Section titled “1. Add an endpoint”In the console, open Webhooks, add your HTTPS URL and pick events. Copy the signing secret (whsec_...).
2. Verify and handle
Section titled “2. Verify and handle”// Node with Expressimport express from 'express';import { createHmac, timingSafeEqual } from 'node:crypto';
const app = express();app.post('/airfone', express.raw({ type: 'application/json' }), (req, res) => { const header = req.get('AirFone-Signature') ?? ''; const parts = Object.fromEntries(header.split(',').map((p) => p.split('='))); const expected = createHmac('sha256', process.env.AIRFONE_WEBHOOK_SECRET) .update(`${parts.t}.${req.body}`).digest('hex'); const fresh = Math.abs(Date.now() / 1000 - Number(parts.t)) < 300; if (!fresh || !parts.v1 || !timingSafeEqual(Buffer.from(expected), Buffer.from(parts.v1))) { return res.sendStatus(400); } const event = JSON.parse(req.body); if (event.type === 'call.ended') { // event.data.object is the call } res.sendStatus(200);});Verify against the raw body. Parsing and re-serializing JSON changes the bytes and the signature will not match.
3. Send a test event
Section titled “3. Send a test event”In Webhooks, choose your endpoint and press Send test event. Deliveries are listed with the response your server gave, and any delivery can be sent again.
Answer with a 2xx within 10 seconds. Do slow work after you answer. See Webhooks for every event, retries and verification in Python and PHP.