How to set up TBBN webhooks
A webhook is a URL on your server that TBBN calls the moment something happens — an offer is accepted, a trade completes, a Space booking is paid. Use it to keep your own system in sync without polling the API.
There are two kinds:
| Webhook | Events | Set up on |
|---|---|---|
| Merchant webhooks | Trade Engine events: offers, checkout, trades | merchants.tbbnetwork.com → Webhooks |
| Business webhooks | Space booking events | business.tbbnetwork.com → your Business → Webhooks |
Before you start
You need an HTTPS URL on your server that:
- accepts
POSTrequests with a JSON body, - answers with any
2xxstatus within a few seconds (do slow work afterwards), - checks the signature on every request (below).
Add a Merchant webhook
- Sign in at merchants.tbbnetwork.com and select Webhooks.
- Enter your endpoint's URL, for example
https://yourapp.com/webhooks/tbbn. - Select Add endpoint. It's subscribed to
offer.accepted,checkout.startedandtrade.completed. - The endpoint appears in the table with its Signing secret (
whsec_…). Store it on your server.
The full list of events, and how to subscribe to others through the API, is in Webhooks & events.
Add a Business webhook (Space bookings)
You need the Admin or Developer role on the Business.
- Go to business.tbbnetwork.com and open your Business.
- Under Webhooks, enter your endpoint's URL.
- Choose events: Everything, or any of Booking created, Booking paid, Booking completed, Booking cancelled and Booking no-show.
- Select Add webhook. Copy its Signing secret.
Check every delivery is really from TBBN
Each request has a header:
X-TBBN-Signature: t=1767225600,v1=5f2c…
To verify it:
- Read
t(a Unix timestamp) andv1(a hex signature) from the header. - Compute an HMAC-SHA256 of
t, a dot, and the raw request body —${t}.${rawBody}— using your endpoint's signing secret. - Compare it with
v1using a constant-time comparison. - Reject the request if they don't match, or if
tis more than 5 minutes old.
Every TBBN SDK includes verifyWebhookSignature(), which does all of this — see
SDKs.
If your endpoint is down
TBBN retries: three quick attempts, then after 5 minutes, 30 minutes, 2 hours, 6 hours and 12 hours.
After that the delivery is set aside so you can replay it. The same event can arrive more than once —
use its deliveryId to ignore duplicates. Details are in
Webhooks & events.
Turn a webhook off
Select Disable next to it. TBBN stops sending to it immediately.
Common questions
I'm not receiving anything. Check the URL is public HTTPS (not localhost) and returns 2xx.
For local testing, use a tunnelling tool that gives your machine a public URL.
Signatures never match. Make sure you sign the raw body exactly as received — not re-encoded JSON — and that you're using the secret for that specific endpoint.
Do webhooks use my API key? No. Each endpoint has its own signing secret.
Still stuck? Ask in the community or contact us from tbbnetwork.com/contact.