Skip to main content
Prelude can notify your application about events using webhooks. You can configure a webhook URL using the callback_url parameter of your request.

The event object

string
The unique identifier of the event.
string
The type of the event, possible values are:
object
The payload of the event, whose structure depends on the event type.
RFC3339 date string
The timestamp of the event creation.

How to set up your Webhook

To start receiving webhook events in your app, create and register a webhook endpoint by following the steps below. You can register and create one endpoint to handle several different event types at once, or set up individual endpoints for specific events.
1

Implement the handler

Develop a webhook endpoint function to receive event data POST requests.
2

Pass the URL

Add your webhook endpoint URL to your Verification requests to start receiving events.
3

Return OK

Return a 200 OK HTTP response to the POST request to acknowledge receipt of the event. If you don’t, Prelude will retry sending the event with exponential backoff for up to 2 weeks. Retries are spaced progressively further apart (1 min, 2 min, 4 min, … up to 12 hours) to allow your endpoint time to recover if it’s temporarily down.

Delivery Statuses

When we receive a delivery status from the carrier, we send a webhook event with the verify.delivery_status type. The status field in the payload indicates the current state of the message delivery. Here are the possible status values:
Delivery statuses are indicative, but they may not always be fully reliable. Depending on the market, a “delivered” confirmation can indicate delivery to the mobile network operator, the cell tower, or — in some cases — the end user’s handset.
Cost reconciliation can take up to 15 minutes. During this window, the billed amount may not yet reflect the final cost of the message.

Security

Prelude’s webhooks support the following security features:

Webhook Signature

To ensure the authenticity of the webhook events, we use a signature mechanism. The signature is a base64 URL-encoded RSASSA-PSS on the SHA256 hash of the payload. The signature is sent as a string prefixed with rsassa-pss-sha256= in the X-Webhook-Signature header of each request to your webhook endpoint. To enable the webhook signature, go to the Prelude dashboard in the Verify API->Configure->Webhooks section and generate a webhook signing key for your application. You can then verify the signature of the webhook events in your webhook endpoint and process the event only if the signature is valid.
The same signing key is used for both the Verify and Notify APIs.

IP Whitelisting

You should whitelist the following IP addresses to ensure that your webhook endpoint receives events from Prelude: