Webhooks for Go

Send webhooks from your Go service in minutes

One package, one function call per event. Svix handles retries, signing, delivery logs, and a portal for your customers, so you don't build any of it.

go get github.com/svix/svix-webhooks/v2/go
Send an event to every endpoint a customer registeredGo
client, err := svix.New("AUTH_TOKEN", nil)
if err != nil {
	return err
}

_, err = client.Message().Create(
	ctx,
	"customer_123",
	models.MessageIn{
		EventType: "invoice.paid",
		Payload: map[string]any{
			"id":     "inv_1042",
			"status": "paid",
		},
	},
	nil,
)
Receiving webhooks too?

Verify webhooks in Go with one call

The same library verifies webhooks from any platform that sends through Svix. Pass it the raw body and headers, and it checks the signature and timestamp for you.

Verify a webhook in a net/http handlerGo
wh, err := svix.NewWebhook("WEBHOOK_SECRET")
if err != nil {
	log.Fatal(err)
}

http.HandleFunc("/webhooks", func(
	w http.ResponseWriter, r *http.Request,
) {
	payload, err := io.ReadAll(r.Body)
	if err != nil {
		w.WriteHeader(http.StatusBadRequest)
		return
	}
	if wh.Verify(payload, r.Header) != nil {
		w.WriteHeader(http.StatusBadRequest)
		return
	}
	// Authentic event: handle it
	w.WriteHeader(http.StatusNoContent)
})
What you don't build

The hard parts are already done

Sending the POST is the easy part. Svix runs everything that makes webhooks hold up in production, so you don't write it, page on it, or maintain it.

Idiomatic Go

Context-aware calls, typed models, and verification that takes a plain []byte and http.Header, so it works with net/http, Gin, Echo, or Chi.

Retries

Failed deliveries retry with exponential backoff for more than a day, and endpoints that keep failing are disabled automatically.

Signing

Every message is signed to the Standard Webhooks spec, with a timestamp that blocks replay attacks.

A portal for your customers

Embed a white-labeled portal where customers add endpoints, pick event types, and debug deliveries themselves.

Delivery logs

Every attempt, response, and status code is searchable, so you never have to grep for a lost webhook.

Replay and recovery

Resend a single message or recover everything that failed since an outage, in one click or one API call.

Clerk

“The highest praise you can give any piece of technology is: it just works. Svix lives up to that. It just works, and that's what it's supposed to do.”

Braden SidotiCo-founder & CTO, Clerk
On Svix for more than three years
Read the full story

Startups get $12,000 in free credits

Incorporated in the last three years and raised $7M or less? Get $1,000 a month in Svix credits for a year, plus hands-on onboarding from our team. Companies in the current YC batch get $50,000.

Is there an official Svix library for Go?

Yes. github.com/svix/svix-webhooks/v2/go is MIT-licensed, covers the full Svix API, and includes webhook verification.

Which Go web frameworks does verification work with?

Any of them. Verify takes the raw request body as []byte and the request's http.Header, which net/http, Gin, Echo, and Chi all expose.

Why does verification need the raw body?

The signature is computed over the exact bytes that were sent. Decoding and re-encoding the JSON first can change those bytes and make a valid webhook fail verification.

Join the newsletter