Webhooks for TypeScript

Send webhooks from your TypeScript API in minutes

One npm package, typed end to end. Svix handles retries, signing, delivery logs, and a portal for your customers, so you don't build any of it.

npm install svix
Send an event to every endpoint a customer registeredTypeScript
import { Svix } from "svix";

const svix = new Svix("AUTH_TOKEN");

await svix.message.create("customer_123", {
  eventType: "invoice.paid",
  payload: { id: "inv_1042", status: "paid" },
});
Receiving webhooks too?

Verify webhooks in TypeScript with one call

The same library verifies webhooks from any platform that sends through Svix. Pass it the raw body and headers, and it checks the signature and timestamp for you.

Verify a webhook in a Web-standard route handlerTypeScript
import { Webhook } from "svix";

const wh = new Webhook(process.env.SECRET!);

export async function POST(req: Request) {
  // Verify the raw body, before parsing it
  const body = await req.text();
  const headers = Object.fromEntries(req.headers);
  try {
    wh.verify(body, headers);
  } catch {
    return new Response(null, { status: 400 });
  }

  // Authentic event: safe to parse and handle
  await handleEvent(JSON.parse(body));
  return new Response(null, { status: 204 });
}
What you don't build

The hard parts are already done

Sending the POST is the easy part. Svix runs everything that makes webhooks hold up in production, so you don't write it, page on it, or maintain it.

Typed end to end

Written in TypeScript, with types for every request and response, so your editor catches a bad event payload before your customers do.

Retries

Failed deliveries retry with exponential backoff for more than a day, and endpoints that keep failing are disabled automatically.

Signing

Every message is signed to the Standard Webhooks spec, with a timestamp that blocks replay attacks.

A portal for your customers

Embed a white-labeled portal where customers add endpoints, pick event types, and debug deliveries themselves.

Delivery logs

Every attempt, response, and status code is searchable, so you never have to grep for a lost webhook.

Replay and recovery

Resend a single message or recover everything that failed since an outage, in one click or one API call.

By the numbers

The svix package is already in a lot of lockfiles

Platforms that send through Svix point their developers at the same package to verify webhooks, so it may already be a dependency of yours.

28M

downloads of the svix package in the last month

Source: npm, September 5 to October 4, 2026
Resend

“We started by offering an API, and very quickly, much more quickly than I thought, people were bringing up webhooks all the time. They all said it's great that we have an API, but what about webhooks?”

Zeno RochaCo-Founder & CEO, Resend
200 to 150,000 users200M+ webhooks a year
Read the full story

Startups get $12,000 in free credits

Incorporated in the last three years and raised $7M or less? Get $1,000 a month in Svix credits for a year, plus hands-on onboarding from our team. Companies in the current YC batch get $50,000.

Does it work in plain JavaScript too?

Yes. The svix package is written in TypeScript and ships compiled JavaScript (ES modules) alongside its type definitions, so plain JavaScript projects can use it too.

Which frameworks does verification work with?

Any framework that gives you the raw request body and headers: Next.js route handlers, Express with express.raw(), Fastify, Hono, and others.

Why does verification need the raw body?

The signature is computed over the exact bytes that were sent. Parsing the JSON and serializing it again can change those bytes and make a valid webhook fail verification.

Join the newsletter