Webhooks
Receive HTTP POST callbacks from RPC providers when accounts or transactions match your filters - event-driven indexing without maintaining WebSocket or gRPC clients.
Search across all documentation pages
Receive HTTP POST callbacks from RPC providers when accounts or transactions match your filters - event-driven indexing without maintaining WebSocket or gRPC clients.
Quick-reference recipe card - copy-paste ready.
# Provider dashboard: create webhook
# URL: https://api.yourapp.com/webhooks/helius
# Type: enhanced transaction / account / raw
# Account addresses: YOUR_PROGRAM_ID// Next.js route handler (illustrative)
export async function POST(req: Request) {
const body = await req.json();
// verify auth header / signature per provider docs
await enqueueForIndexer(body);
return new Response("ok");
}When to reach for this:
import { createHmac, timingSafeEqual } from "node:crypto";
function verifyHeliusSignature(
secret: string,
payload: string,
header: string | null
): boolean {
if (!header) return false;
const expected = createHmac("sha256", secret).update(payload).digest("hex");
try {
return timingSafeEqual(Buffer.from(header), Buffer.from(expected));
} catch {
return false;
}
}
export async function POST(req: Request) {
const raw = await req.text();
const sig = req.headers.get("x-helius-signature");
if (!verifyHeliusSignature(process.env.HELIUS_WEBHOOK_SECRET!, raw, sig)) {
return new Response("unauthorized", { status: 401 });
}
const event = JSON.parse(raw);
await persistTransactionEvent(event);
return Response.json({ received: true });
}What this demonstrates:
| Choice | Recommendation |
|---|---|
| Auth | HMAC header verification |
| Response time | < 1s ACK, async process |
| Idempotency | Key on signature + type |
| Storage | Raw JSON + normalized tables |
// Fast ACK pattern with queue
await queue.add("index-tx", { id: event.signature });
return Response.json({ ok: true });| Alternative | Use When | Don't Use When |
|---|---|---|
| Yellowstone gRPC | Massive throughput | Simple alert triggers |
logsSubscribe | You control WS infra | Serverless-only stack |
| Cron GPA scans | Low frequency | Near-real-time needs |
| Internal cron + getSignaturesForAddress | Tiny address sets | High volume programs |
Helius prominently; others offer similar enhanced callbacks - check dashboards.
Often for alerts; analytics still need database schema and backfill for completeness.
Use ngrok/cloudflared tunnel to HTTPS endpoint during development.
Provider retries; reconcile gaps with signature backfill from last known slot.
Enhanced saves parse work; raw gives full control if program is custom.
Separate webhook URLs and secrets for staging vs production.
Provider plans cap events per month - monitor usage dashboard.
Provider-dependent - many focus on mainnet production.
Follow vendor doc for exact header names and HMAC algorithm.
Different product surface - webhooks for events, DAS for asset reads.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 16, 2026