{"id":13828248,"url":"https://github.com/spatie/laravel-webhook-server","last_synced_at":"2026-02-21T17:05:02.715Z","repository":{"id":38374995,"uuid":"191252974","full_name":"spatie/laravel-webhook-server","owner":"spatie","description":"Send webhooks from Laravel apps","archived":false,"fork":false,"pushed_at":"2026-02-09T15:47:53.000Z","size":257,"stargazers_count":1049,"open_issues_count":0,"forks_count":139,"subscribers_count":17,"default_branch":"main","last_synced_at":"2026-02-09T19:53:25.556Z","etag":null,"topics":["http","laravel","webhooks"],"latest_commit_sha":null,"homepage":"https://freek.dev/1383-sending-and-receiving-webhooks-in-laravel-apps","language":"PHP","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/spatie.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"custom":"https://spatie.be/open-source/support-us"}},"created_at":"2019-06-10T22:14:15.000Z","updated_at":"2026-02-09T15:47:57.000Z","dependencies_parsed_at":"2024-01-18T05:20:58.396Z","dependency_job_id":"edf62718-18de-464a-9ccd-e0b4e31c6a21","html_url":"https://github.com/spatie/laravel-webhook-server","commit_stats":{"total_commits":240,"total_committers":39,"mean_commits":6.153846153846154,"dds":0.3666666666666667,"last_synced_commit":"e172d81b23ef4787228bd666907d3edd5f1cf8e6"},"previous_names":[],"tags_count":52,"template":false,"template_full_name":"spatie/package-skeleton-laravel","purl":"pkg:github/spatie/laravel-webhook-server","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spatie%2Flaravel-webhook-server","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spatie%2Flaravel-webhook-server/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spatie%2Flaravel-webhook-server/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spatie%2Flaravel-webhook-server/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/spatie","download_url":"https://codeload.github.com/spatie/laravel-webhook-server/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spatie%2Flaravel-webhook-server/sbom","scorecard":{"id":840636,"data":{"date":"2025-08-11","repo":{"name":"github.com/spatie/laravel-webhook-server","commit":"28195dac21cc8d44ed4f97a5dda8ab29be67bb17"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.7,"checks":[{"name":"Code-Review","score":3,"reason":"Found 6/16 approved changesets -- score normalized to 3","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"1 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/php-cs-fixer.yml:1","Warn: no topLevel permission defined: .github/workflows/run-tests.yml:1","Warn: no topLevel permission defined: .github/workflows/update-changelog.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/php-cs-fixer.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/spatie/laravel-webhook-server/php-cs-fixer.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/php-cs-fixer.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/spatie/laravel-webhook-server/php-cs-fixer.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/php-cs-fixer.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/spatie/laravel-webhook-server/php-cs-fixer.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/spatie/laravel-webhook-server/run-tests.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/run-tests.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/spatie/laravel-webhook-server/run-tests.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-changelog.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/spatie/laravel-webhook-server/update-changelog.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-changelog.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/spatie/laravel-webhook-server/update-changelog.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-changelog.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/spatie/laravel-webhook-server/update-changelog.yml/main?enable=pin","Info:   0 out of   3 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   5 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE.md:0","Info: FSF or OSI recognized license: MIT License: LICENSE.md:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 20 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-23T20:24:09.596Z","repository_id":38374995,"created_at":"2025-08-23T20:24:09.596Z","updated_at":"2025-08-23T20:24:09.596Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29688218,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-21T15:51:39.154Z","status":"ssl_error","status_checked_at":"2026-02-21T15:49:03.425Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["http","laravel","webhooks"],"created_at":"2024-08-04T09:02:38.344Z","updated_at":"2026-02-21T17:05:02.709Z","avatar_url":"https://github.com/spatie.png","language":"PHP","funding_links":["https://spatie.be/open-source/support-us"],"categories":["PHP"],"sub_categories":[],"readme":"\u003cdiv align=\"left\"\u003e\n    \u003ca href=\"https://spatie.be/open-source?utm_source=github\u0026utm_medium=banner\u0026utm_campaign=laravel-webhook-server\"\u003e\n      \u003cpicture\u003e\n        \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://spatie.be/packages/header/laravel-webhook-server/html/dark.webp\"\u003e\n        \u003cimg alt=\"Logo for laravel-webhook-server\" src=\"https://spatie.be/packages/header/laravel-webhook-server/html/light.webp\"\u003e\n      \u003c/picture\u003e\n    \u003c/a\u003e\n\n\u003ch1\u003eSend webhooks from Laravel apps\u003c/h1\u003e\n\n[![Latest Version on Packagist](https://img.shields.io/packagist/v/spatie/laravel-webhook-server.svg?style=flat-square)](https://packagist.org/packages/spatie/laravel-webhook-server)\n[![run-tests](https://github.com/spatie/laravel-webhook-server/actions/workflows/run-tests.yml/badge.svg)](https://github.com/spatie/laravel-webhook-server/actions/workflows/run-tests.yml)[![Total Downloads](https://img.shields.io/packagist/dt/spatie/laravel-webhook-server.svg?style=flat-square)](https://packagist.org/packages/spatie/laravel-webhook-server)\n    \n\u003c/div\u003e\n\nA webhook is a way for an app to provide information to another app about a particular event. The way the two apps communicate is with a simple HTTP request. \n\nThis package allows you to configure and send webhooks in a Laravel app easily. It has support for [signing calls](https://github.com/spatie/laravel-webhook-server#how-signing-requests-works), [retrying calls and backoff strategies](https://github.com/spatie/laravel-webhook-server#retrying-failed-webhooks).\n\nIf you need to receive and process webhooks take a look at our [laravel-webhook-client](https://github.com/spatie/laravel-webhook-client) package.\n\n## Support us\n\n[\u003cimg src=\"https://github-ads.s3.eu-central-1.amazonaws.com/laravel-webhook-server.jpg?t=1\" width=\"419px\" /\u003e](https://spatie.be/github-ad-click/laravel-webhook-server)\n\nWe invest a lot of resources into creating [best in class open source packages](https://spatie.be/open-source). You can support us by [buying one of our paid products](https://spatie.be/open-source/support-us).\n\nWe highly appreciate you sending us a postcard from your hometown, mentioning which of our package(s) you are using. You'll find our address on [our contact page](https://spatie.be/about-us). We publish all received postcards on [our virtual postcard wall](https://spatie.be/open-source/postcards).\n\n## Installation\n\nYou can install the package via composer:\n\n```bash\ncomposer require spatie/laravel-webhook-server\n```\n\nYou can publish the config file with:\n```bash\nphp artisan vendor:publish --provider=\"Spatie\\WebhookServer\\WebhookServerServiceProvider\"\n```\n\nThis is the contents of the file that will be published at `config/webhook-server.php`:\n\n```php\nreturn [\n\n    /*\n     *  The default queue that should be used to send webhook requests.\n     */\n    'queue' =\u003e 'default',\n\n    /*\n     * The default http verb to use.\n     */\n    'http_verb' =\u003e 'post',\n\n    /*\n     * This class is responsible for calculating the signature that will be added to\n     * the headers of the webhook request. A webhook client can use the signature\n     * to verify the request hasn't been tampered with.\n     */\n    'signer' =\u003e \\Spatie\\WebhookServer\\Signer\\DefaultSigner::class,\n\n    /*\n     * This is the name of the header where the signature will be added.\n     */\n    'signature_header_name' =\u003e 'Signature',\n    \n    /*\n     * This is the name of the header where the timestamp will be added.\n     */\n    'timestamp_header_name' =\u003e 'Timestamp',\n\n    /*\n     * These are the headers that will be added to all webhook requests.\n     */\n    'headers' =\u003e [],\n\n    /*\n     * If a call to a webhook takes longer this amount of seconds\n     * the attempt will be considered failed.\n     */\n    'timeout_in_seconds' =\u003e 3,\n\n    /*\n     * The amount of times the webhook should be called before we give up.\n     */\n    'tries' =\u003e 3,\n\n    /*\n     * This class determines how many seconds there should be between attempts.\n     */\n    'backoff_strategy' =\u003e \\Spatie\\WebhookServer\\BackoffStrategy\\ExponentialBackoffStrategy::class,\n        \n    /*\n     * This class is used to dispatch webhooks onto the queue.\n     */\n    'webhook_job' =\u003e \\Spatie\\WebhookServer\\CallWebhookJob::class,\n\n    /*\n     * By default we will verify that the ssl certificate of the destination\n     * of the webhook is valid.\n     */\n    'verify_ssl' =\u003e true,\n    \n    /*\n     * When set to true, an exception will be thrown when the last attempt fails\n     */\n    'throw_exception_on_failure' =\u003e false,\n\n    /*\n     * When using Laravel Horizon you can specify tags that should be used on the\n     * underlying job that performs the webhook request.\n     */\n    'tags' =\u003e [],\n];\n```\n\nBy default, the package uses queues to retry failed webhook requests. Be sure to set up a real queue other than `sync` in non-local environments.\n\n## Usage\n\nThis is the simplest way to call a webhook:\n\n```php\nWebhookCall::create()\n   -\u003eurl('https://other-app.com/webhooks')\n   -\u003epayload(['key' =\u003e 'value'])\n   -\u003euseSecret('sign-using-this-secret')\n   -\u003edispatch();\n```\n\nThis will send a post request to `https://other-app.com/webhooks`. The body of the request will be JSON encoded version of the array passed to `payload`. The request will have a header called `Signature` that will contain a signature the receiving app can use [to verify](https://github.com/spatie/laravel-webhook-server#how-signing-requests-works) the payload hasn't been tampered with. Dispatching a webhook call will also fire a `DispatchingWebhookCallEvent`.\n\nIf the receiving app doesn't respond with a response code starting with `2`, the package will retry calling the webhook after 10 seconds. If that second attempt fails, the package will attempt to call the webhook a final time after 100 seconds. Should that attempt fail, the `FinalWebhookCallFailedEvent` will be raised.\n\n### Send webhook synchronously\n\nIf you would like to call the webhook immediately (synchronously), you may use the dispatchSync method. When using this method, the webhook will not be queued and will be run immediately. This can be helpful in situations where sending the webhook is part of a bigger job that already has been queued.\n\n```php\nWebhookCall::create()\n   ...\n   -\u003edispatchSync();\n```\n\n### Conditionally sending webhooks\n\nIf you would like to conditionally dispatch a webhook, you may use the `dispatchIf`, `dispatchUnless`, `dispatchSyncIf`, and `dispatchSyncUnless` methods:\n\n```php\nWebhookCall::create()\n   ...\n   -\u003edispatchIf($condition);\n\nWebhookCall::create()\n   ...\n   -\u003edispatchUnless($condition);\n\nWebhookCall::create()\n   ...\n   -\u003edispatchSyncIf($condition);\n\nWebhookCall::create()\n   ...\n   -\u003edispatchSyncUnless($condition);\n```\n\n### How signing requests work\n\nWhen setting up, it's common to generate, store, and share a secret between your app and the app that wants to receive webhooks. Generating the secret could be done with `Illuminate\\Support\\Str::random()`, but it's entirely up to you. The package will use the secret to sign a webhook call.\n\nBy default, the package will add a header called `Signature` that will contain a signature the receiving app can use if the payload hasn't been tampered with. This is how that signature is calculated:\n\n```php\n// payload is the array passed to the `payload` method of the webhook\n// secret is the string given to the `signUsingSecret` method on the webhook.\n\n$payloadJson = json_encode($payload); \n\n$signature = hash_hmac('sha256', $payloadJson, $secret);\n```\n\n### Skip signing request\n\nWe don't recommend this, but if you don't want the webhook request to be signed call the `doNotSign` method.\n\n```php\nWebhookCall::create()\n   -\u003edoNotSign()\n    ...\n```\n\nBy calling this method, the `Signature` header will not be set.\n\n### Customizing signing requests\n\nIf you want to customize the signing process, you can create your own custom signer. A signer is any class that implements `Spatie\\WebhookServer\\Signer`.\n\nThis is what that interface looks like.\n\n```php\nnamespace Spatie\\WebhookServer\\Signer;\n\ninterface Signer\n{\n    public function signatureHeaderName(): string;\n\n    public function calculateSignature(array $payload, string $secret): string;\n}\n```\n\nAfter creating your signer, you can specify its class name in the `signer` key of the `webhook-server` config file. Your signer will then be used by default in all webhook calls.\n\nYou can also specify a signer for a specific webhook call:\n\n```php\nWebhookCall::create()\n    -\u003esignUsing(YourCustomSigner::class)\n    ...\n    -\u003edispatch();\n```\n\nIf you want to customize the name of the header, you don't need to use a custom signer, but you can change the value in the `signature_header_name` in the `webhook-server` config file.\n\n### Use Timestamp\n\nThis is highly recommended to help prevent replay attacks.\n\nTimestamping is disabled by default, but you can enable it by calling `useTimestamp()` method.\n\n```php\nWebhookCall::create()\n    -\u003euseTimestamp()\n    ...\n    -\u003edispatch();\n```\n\nBy calling this method, the `Timestamp` header will be set.\n\n### Retrying failed webhooks\n\nWhen the app to which we're sending the webhook fails to send a response with a `2xx` status code the package will consider the call as failed. The call will also be considered failed if the remote app doesn't respond within 3 seconds.\n\nYou can configure that default timeout in the `timeout_in_seconds` key of the `webhook-server` config file. Alternatively, you can override the timeout for a specific webhook like this:\n\n```php\nWebhookCall::create()\n    -\u003etimeoutInSeconds(5)\n    ...\n    -\u003edispatch();\n```\n\nWhen a webhook call fails, we'll retry the call two more times. You can set the default amount of times we retry the webhook call in the `tries` key of the config file. Alternatively, you can specify the number of tries for a specific webhook like this:\n\n```php\nWebhookCall::create()\n    -\u003emaximumTries(5)\n    ...\n    -\u003edispatch();\n```\n\nTo not hammer the remote app we'll wait some time between each attempt. By default, we wait 10 seconds between the first and second attempts, 100 seconds between the third and the fourth, 1000 between the fourth and the fifth, and so on. The maximum amount of seconds that we'll wait is 100 000, which is about 27 hours. This behavior is implemented in the default `ExponentialBackoffStrategy`.\n\nYou can define your own backoff strategy by creating a class that implements `Spatie\\WebhookServer\\BackoffStrategy\\BackoffStrategy`. This is what that interface looks like:\n\n```php\nnamespace Spatie\\WebhookServer\\BackoffStrategy;\n\ninterface BackoffStrategy\n{\n    public function waitInSecondsAfterAttempt(int $attempt): int;\n}\n```\n\nYou can make your custom strategy the default strategy by specifying its fully qualified class name in the `backoff_strategy` of the `webhook-server` config file. Alternatively, you can specify a strategy for a specific webhook like this.\n\n```php\nWebhookCall::create()\n    -\u003euseBackoffStrategy(YourBackoffStrategy::class)\n    ...\n    -\u003edispatch();\n```\n\nUnder the hood, the retrying of the webhook calls is implemented using [delayed dispatching](https://laravel.com/docs/master/queues#delayed-dispatching). Amazon SQS only has support for a small maximum delay. If you're using Amazon SQS for your queues, make sure you do not configure the package in a way so there are more than 15 minutes between each attempt.\n\n### Customizing the HTTP verb\n\nBy default, all webhooks will use the `post` method. You can customize that by specifying the HTTP verb you want in the `http_verb` key of the `webhook-server` config file.\n\nYou can also override the default for a specific call by using the `useHttpVerb` method.\n\n```php\nWebhookCall::create()\n    -\u003euseHttpVerb('get')\n    ...\n    -\u003edispatch();\n```\n\n### Adding extra headers\n\nYou can use extra headers by adding them to the `headers` key in the `webhook-server` config file. If you want to add additional headers for a specific webhook, you can use the `withHeaders` call.\n\n```php\nWebhookCall::create()\n    -\u003ewithHeaders([\n        'Another Header' =\u003e 'Value of Another Header'\n    ])\n    ...\n    -\u003edispatch();\n```\n\n### Using a proxy\n\nYou can direct webhooks through a proxy by specifying the `proxy` key in the `webhook-server` config file. To set a proxy for a specific\nrequest, you can use the `useProxy` call.\n\n```php\nWebhookCall::create()\n    -\u003euseProxy('http://proxy.server:3128')\n    ...\n```\n\n### Using mutual TLS authentication\n\nTo safeguard the integrity of webhook data transmission, it's critical to authenticate the intended recipient of your webhook payload. \nMutual TLS authentication serves as a robust method for this purpose. Contrary to standard TLS, where only the client verifies the server, \nmutual TLS requires both the webhook endpoint (acting as the client) and the webhook provider (acting as the server) to authenticate each other. \nThis is achieved through an exchange of certificates during the TLS handshake, ensuring that both parties confirm each other's identity.\n\n\u003e Note: If you need to include your own certificate authority, pass the certificate path to the `verifySsl()` method.\n\n```php\nWebhookCall::create()\n    -\u003emutualTls(\n        certPath: storage_path('path/to/cert.pem'), \n        certPassphrase: 'optional_cert_passphrase', \n        sslKeyPath: storage_path('path/to/key.pem'), \n        sslKeyPassphrase: 'optional_key_passphrase'\n    )\n```\n\nThe proxy specification follows the [guzzlehttp proxy format](https://docs.guzzlephp.org/en/stable/request-options.html#proxy)\n\n### Verifying the SSL certificate of the receiving app\n\nWhen using a URL that starts with `https://` the package will verify if the SSL certificate of the receiving party is valid. If it is not, we will consider the webhook call failed. We don't recommend this, but you can turn off this verification by setting the `verify_ssl` key in the `webhook-server` config file to `false`.\n\nYou can also disable the verification per webhook call with the `doNotVerifySsl` method.\n\n```php\nWebhookCall::create()\n    -\u003edoNotVerifySsl()\n    ...\n    -\u003edispatch();\n```\n\n### Adding meta information\n\nYou can add extra meta information to the webhook. This meta information will not be transmitted, and it will only be used to pass to [the events this package fires](#events).\n\nThis is how you can add meta information:\n\n```php\nWebhookCall::create()\n    -\u003emeta($arrayWithMetaInformation)\n    ...\n    -\u003edispatch();\n```\n\n### Adding tags\n\nIf you're using [Laravel Horizon](https://laravel.com/docs/5.8/horizon) for your queues, you'll be happy to know that we support [tags](https://laravel.com/docs/5.8/horizon#tags). \n\nTo add tags to the underlying job that'll perform the webhook call, simply specify them in the `tags` key of the `webhook-server` config file or use the `withTags` method:\n\n```php\nWebhookCall::create()\n    -\u003ewithTags($tags)\n    ...\n    -\u003edispatch();\n```\n\n### Exception handling\nBy default, the package will not log any exceptions that are thrown when sending a webhook.\n\nTo handle exceptions you need to create listeners for the `Spatie\\WebhookServer\\Events\\WebhookCallFailedEvent` and/or `Spatie\\WebhookServer\\Events\\FinalWebhookCallFailedEvent` events.\n\n#### Retry failed execution\nBy default, failing jobs will be ignored. To throw an exception when the last attempt of a job fails, you can call `throwExceptionOnFailure` :\n```php\nWebhookCall::create()\n    -\u003ethrowExceptionOnFailure()\n    ...\n    -\u003edispatch();\n```\nor activate the `throw_exception_on_failure` global option of the `webhook-server` config file.\n\n### Sending raw string body instead of JSON\n\nBy default, all webhooks will transform the payload into JSON. Instead of sending JSON, you can send any string by using the `sendRawBody(string $body)` option instead.\n\nDue to a type mismatch in the Signer API, it is currently not supported to sign raw data requests.\nWhen using the _sendRawBody_ option, you will receive a _string_ payload in the WebhookEvents.\n```php\nWebhookCall::create()\n    -\u003esendRawBody(\"\u003croot\u003esomeXMLContent\u003c/root\u003e\")\n    -\u003edoNotSign()\n    ...\n    -\u003edispatch();\n```\n\n### Events\n\nThe package fires these events:\n- `DispatchingWebhookCallEvent`: right before the webhook call will be dispatched to the queue.\n- `WebhookCallSucceededEvent`: the remote app responded with a `2xx` response code.\n- `WebhookCallFailedEvent`: the remote app responded with a non `2xx` response code, or it did not respond at all.\n- `FinalWebhookCallFailedEvent`: the final attempt to call the webhook failed.\n\nAll these events have these properties:\n\n- `httpVerb`: the verb used to perform the request\n- `webhookUrl`: the URL to where the request was sent\n- `payload`: the used payload\n- `headers`: the headers that were sent. This array includes the signature header\n- `meta`: the array of values passed to the webhook with [the `meta` call](#adding-meta-information)\n- `tags`: the array of [tags](#adding-tags) used\n- `uuid`: a unique string to identify this call. This uuid will be the same for all attempts of a webhook call.\n\nExcept for the `DispatchingWebhookCallEvent`, all events have these additional properties:\n\n- `attempt`: the attempt number\n- `response`: the response returned by the remote app. Can be an instance of `\\GuzzleHttp\\Psr7\\Response` or `null`.\n\n## Testing\n\n``` bash\ncomposer test\n```\n\n## Testing Webhooks\nWhen using the package in automated tests, you'll want to perform one of the following to ensure that no webhooks are sent out to genuine websites\n\n### Bus\n```php \nuse Illuminate\\Support\\Facades\\Bus;\nuse Spatie\\WebhookServer\\CallWebhookJob;\nuse Tests\\TestCase;\n\nclass TestFile extends TestCase\n{\n    public function testJobIsDispatched()\n    {\n        Bus::fake();\n\n        ... Perform webhook call ...\n\n        Bus::assertDispatched(CallWebhookJob::class);\n    }\n}\n```\n\n### Queue\n```php \nuse Illuminate\\Support\\Facades\\Queue;\nuse Spatie\\WebhookServer\\CallWebhookJob;\nuse Tests\\TestCase;\n\nclass TestFile extends TestCase\n{\n    public function testJobIsQueued()\n    {\n        Queue::fake();\n\n        ... Perform webhook call ...\n\n        Queue::assertPushed(CallWebhookJob::class);\n    }\n}\n```\n\n## Changelog\n\nPlease see [CHANGELOG](CHANGELOG.md) for more information on what has changed recently.\n\n## Contributing\n\nPlease see [CONTRIBUTING](https://github.com/spatie/.github/blob/main/CONTRIBUTING.md) for details.\n\n### Security\n\nIf you discover any security-related issues, please email freek@spatie.be instead of using the issue tracker.\n\n## Postcardware\n\nYou're free to use this package, but if it makes it to your production environment, we highly appreciate you sending us a postcard from your hometown, mentioning which of our package(s) you are using.\n\nOur address is: Spatie, Kruikstraat 22, 2018 Antwerp, Belgium.\n\nWe publish all received postcards [on our company website](https://spatie.be/en/opensource/postcards).\n\n## Credits\n\n- [Freek Van der Herten](https://github.com/freekmurze)\n- [All Contributors](../../contributors)\n\n## License\n\nThe MIT License (MIT). Please see [License File](LICENSE.md) for more information.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fspatie%2Flaravel-webhook-server","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fspatie%2Flaravel-webhook-server","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fspatie%2Flaravel-webhook-server/lists"}