GitHub

Receive GitHub webhooks with signature verification.

Set the secret when you create the webhook in your repository or organization settings. The provider verifies the x-hub-signature-256 header, reads the delivery id from x-github-delivery, and the event name from x-github-event.

app/api/webhooks/github/route.ts
import { webhook, github } from "next-webhooks";

export const POST = webhook({
  provider: github({ secret: process.env.GITHUB_WEBHOOK_SECRET! }),
  handler: async (event) => {
    if (event.type === "push") {
      // event.payload has ref, commits, repository, and so on
    }
    if (event.type === "pull_request") {
      // ...
    }
  },
});

Notes

  • Deliveries are deduplicated by the x-github-delivery id automatically
  • GitHub sends a ping event when you register the webhook; a 200 is enough