Skip to content

Receive webhooks

In the console, open Webhooks, add your HTTPS URL and pick events. Copy the signing secret (whsec_...).

// Node with Express
import express from 'express';
import { createHmac, timingSafeEqual } from 'node:crypto';
const app = express();
app.post('/airfone', express.raw({ type: 'application/json' }), (req, res) => {
const header = req.get('AirFone-Signature') ?? '';
const parts = Object.fromEntries(header.split(',').map((p) => p.split('=')));
const expected = createHmac('sha256', process.env.AIRFONE_WEBHOOK_SECRET)
.update(`${parts.t}.${req.body}`).digest('hex');
const fresh = Math.abs(Date.now() / 1000 - Number(parts.t)) < 300;
if (!fresh || !parts.v1 || !timingSafeEqual(Buffer.from(expected), Buffer.from(parts.v1))) {
return res.sendStatus(400);
}
const event = JSON.parse(req.body);
if (event.type === 'call.ended') {
// event.data.object is the call
}
res.sendStatus(200);
});

Verify against the raw body. Parsing and re-serializing JSON changes the bytes and the signature will not match.

In Webhooks, choose your endpoint and press Send test event. Deliveries are listed with the response your server gave, and any delivery can be sent again.

Answer with a 2xx within 10 seconds. Do slow work after you answer. See Webhooks for every event, retries and verification in Python and PHP.