Glossary
Webhook
TL;DR
Webhooks follow a push model: instead of your application repeatedly asking 'is the document signed yet?', the e-signature provider tells you the moment it happens. You register a URL during document creation, and the provider POSTs event data to that URL as a JSON payload.
**Signbee webhook events**
Signbee currently supports one event: • document.signed — recipient completed signing (Pro and Business plans only)
Free plans receive HTTP 403 when attempting to use webhooks. Both parties still receive email delivery of the signed PDF on all plans. Polling via GET /api/v1/documents/{id} works as a fallback on all plans.
**Why webhooks matter for production systems**
Polling is wasteful and unreliable. A webhook delivers the event in real-time (typically within 1-5 seconds), letting you trigger downstream workflows immediately: update a CRM, start an onboarding flow, process a payment, or notify a team.
**Webhook security**
Always verify webhook authenticity using HMAC signatures. Signbee includes an X-Signbee-Signature header containing an HMAC-SHA256 hex digest of the raw POST body. Your server should verify this signature before processing the event. Also: use HTTPS, respond with 200 within 5 seconds (process asynchronously), and make handlers idempotent.
**Provider comparison**
DocuSign calls their webhook system 'Connect' and requires dashboard configuration. HelloSign uses callback URLs. Signbee sends webhook notifications to any registered URL with HMAC verification headers.
Related terms
Further reading
Related resources
Try Signbee — e-signatures via API.