Buy Me a Coffee Webhooks

Server-push HTTP webhooks configured in the dashboard (Integrations - New webhook). Buy Me a Coffee POSTs a JSON event envelope to a subscriber URL for donation, membership / recurring-donation, extra purchase, commission, and wishlist events. Each request is signed with an HMAC-SHA256 signature in the x-signature-sha256 header. This is server-to-endpoint HTTP, not a WebSocket.

API entry from apis.yml

apis.yml Raw ↑
aid: buymeacoffee:buymeacoffee-webhooks-api
name: Buy Me a Coffee Webhooks
tags:
- Webhooks
- Events
- Notifications
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/apis-json-logo.jpg
humanURL: https://help.buymeacoffee.com/en/articles/15743173-how-to-setup-and-use-buy-me-a-coffee-webhooks
baseURL: https://developers.buymeacoffee.com/api/v1
properties:
- url: https://help.buymeacoffee.com/en/articles/15743173-how-to-setup-and-use-buy-me-a-coffee-webhooks
  type: Documentation
description: Server-push HTTP webhooks configured in the dashboard (Integrations - New webhook). Buy Me
  a Coffee POSTs a JSON event envelope to a subscriber URL for donation, membership / recurring-donation,
  extra purchase, commission, and wishlist events. Each request is signed with an HMAC-SHA256 signature
  in the x-signature-sha256 header. This is server-to-endpoint HTTP, not a WebSocket.
Where this information came from

This is an independent, third-party profile of Buy Me a Coffee Webhooks, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.