Skip to main content
A webhook is configured the same way regardless of how you set it up, with a destination url, at least one trigger, and optionally how Yuno authenticates to your endpoint. See Events and Triggers for the full catalog of events you can select.
  1. Navigate to the Developers tab
  2. Click Webhooks
  3. Click Add webhook
A sidebar will open where you’ll configure:
  • Name: Identify your webhook
  • Endpoint URL: Your server URL to receive notifications
  • x-api-key: Your API key, sent in notification headers (api_key via the API)
  • x-secret: Your secret, sent in notification headers (secret via the API)
  • Use OAuth2 Authentication: Optional checkbox for OAuth2
  • Use HMAC Authentication: Optional checkbox for HMAC signature verification
  • Trigger on: Select which events will trigger this webhook (enrollment, payment, subscription, etc.)
Once configured, the webhook will send notifications whenever the selected events occur. The image below shows the side panel to add a webhook.
In the Yuno dashboard Developers tab, you can activate and deactivate webhooks using the Status toggle button.
Access the Payloads and Examples page to check examples for payment, enrollment, and many other notification events.

HMAC authentication

Check Use HMAC Authentication in the dashboard, or set hmac_client_secret via the API. Either way, Yuno uses that key to generate an HMAC-SHA256 signature and sends it in the x-hmac-signature header with each delivery, so you can verify a webhook genuinely came from Yuno and wasn’t tampered with. See the Verify Webhook Signatures (HMAC) guide for implementation details.

OAuth2

Check Use OAuth2 Authentication in the dashboard, or set the matching fields via the API, so Yuno can obtain the token it sends with each delivery:
The API also exposes oauth2_scope, oauth2_authorization_name (the header Yuno sends the token in, defaults to Authorization), and oauth2_include_client_id. These don’t have a dashboard equivalent yet. See OAuth2 for the full field reference.