feat.press webhooks
feat.press webhooks docs: HMAC signatures, idempotency, and entitlement lifecycle events for app products.
feat.press webhook signatures
Header feat-signature: t=<unix_seconds>,v1=<hex>.
Header feat-event-id is the idempotency key.
Verify HMAC-SHA256 of the timestamp, a period, and the raw body. Reject timestamps older than 300 seconds with HTTP 400.
Non-2xx responses are retried up to 3 times. Each attempt times out after 8 seconds. User agent: feat-webhooks/1.0.
feat.press entitlement events
webhook.test, entitlement.activated, entitlement.renewed, entitlement.updated, entitlement.cancellation_scheduled, entitlement.past_due, entitlement.expired, entitlement.revoked.
data includes entitlementId, orderId, productId, buyerEmail, status, licenseKeyLast4, tierId, tierName, billingInterval, currentPeriodEnd, cancelAtPeriodEnd, and expiresAt. apiVersion is 2026-07-18.
Official SDK: npm i @feat-press/node. Use createWebhookRoute and npx feat-webhook replay.
Canonical URL: /developers/webhooks. Markdown: Accept: text/markdown or /developers/webhooks.md