railhook / php
Official PHP SDK for Railhook — reliable webhook infrastructure
Requires
- php: >=8.1
- ext-curl: *
- ext-json: *
Requires (Dev)
- phpstan/phpstan: ^1.10 || ^2.0
- phpunit/phpunit: ^10.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
- dev-main
- 3.2.0
- 3.1.0
- 3.0.0
- 2.32.2
- 2.32.1
- 2.32.0
- 2.31.1
- 2.31.0
- 2.30.2
- 2.30.1
- 2.30.0
- 2.29.0
- 2.28.2
- 2.28.1
- 2.28.0
- 2.27.1
- 2.27.0
- 2.26.0
- 2.25.0
- 2.24.0
- 2.23.0
- 2.22.0
- 2.21.2
- 2.21.1
- 2.21.0
- 2.20.13
- 2.20.12
- 2.20.11
- 2.20.10
- 2.20.9
- 2.20.8
- 2.20.7
- 2.20.6
- 2.20.5
- 2.20.4
- 2.20.3
- 2.20.2
- 2.20.1
- 2.20.0
- 2.19.2
- 2.19.1
- 2.19.0
- 2.18.1
- 2.18.0
- 2.17.2
- 2.17.1
- 2.17.0
- 2.16.6
- 2.16.5
- 2.16.4
- 2.16.3
- 2.16.2
- 2.16.1
- 2.16.0
- 2.15.0
- 2.14.0
- 2.13.0
- 2.12.0
- 2.11.0
- 2.10.0
- 2.9.1
- 2.9.0
- 2.8.0
- 2.7.0
- 2.6.1
- 2.2.1
- 2.1.0
- 2.0.0
- 1.1.0
- 1.0.3
This package is auto-updated.
Last update: 2026-09-30 14:16:39 UTC
README
PHP SDK for Railhook. Needs PHP 8.1+, ext-json and ext-curl.
composer require railhook/php
Before 2.12.0 this package was webhook-platform/php with the namespace Hookflow\. That
package is marked abandoned.
Send an event
<?php use Railhook\Railhook; $client = new Railhook( apiKey: getenv('RAILHOOK_API_KEY'), baseUrl: 'https://railhook.io', // default http://localhost:8080 ); $event = $client->events->send( type: 'order.completed', data: ['orderId' => 'ord_123', 'amount' => 99.99], idempotencyKey: 'order-123-completed', // optional ); echo $event['eventId'], ' ', $event['deliveriesCreated'], "\n";
Verify a webhook
The signature covers the raw body, so verify the bytes as received.
<?php use Railhook\Webhook; use Railhook\Exception\RailhookException; try { $event = Webhook::constructEvent( file_get_contents('php://input'), getallheaders(), getenv('WEBHOOK_SECRET'), ); error_log("{$event['eventId']}: " . json_encode($event['data'])); http_response_code(200); } catch (RailhookException $e) { http_response_code(400); }
Webhook::verifyStandardWebhook checks the webhook-* headers instead. During a secret
rotation either secret's signature is accepted.
The client also covers endpoints, subscriptions, deliveries, consumers and portal sessions, and incoming sources and events. It does not retry: one call is one HTTP request.
Full docs: https://railhook.io/docs/tools/sdks/
Develop
composer install composer test php scripts/live-api-smoke.php # against a running stack (make up)
License
MIT