For developers · Checked 1 October 2026

App Store Connect webhooks

Short answer: an App Store Connect webhook is an endpoint on your server that receives HTTP POST requests when something happens to your app, such as an App Store version changing review state, a build upload finishing, an external TestFlight build being approved or a tester sending feedback. You create it in Users and Access → Integrations → Webhooks or with POST /v1/webhooks. Each webhook covers one app, with up to ten per app, and every delivery is signed with HMAC-SHA256 in the x-apple-signature header.

Webhook event types

WebhookEventType values from the App Store Connect API documentation, read 1 October 2026.

Event typeGroup
APP_STORE_VERSION_APP_VERSION_STATE_UPDATEDApp status changes, including review states
BUILD_UPLOAD_STATE_UPDATEDBuild changes
BUILD_BETA_DETAIL_EXTERNAL_BUILD_STATE_UPDATEDExternal TestFlight build state
BETA_FEEDBACK_SCREENSHOT_SUBMISSION_CREATEDBeta feedback with screenshots
BETA_FEEDBACK_CRASH_SUBMISSION_CREATEDBeta feedback with crashes
BACKGROUND_ASSET_VERSION_STATE_UPDATED and three other BACKGROUND_ASSET_VERSION_* eventsApple-hosted background asset packs
ALTERNATIVE_DISTRIBUTION_PACKAGE_AVAILABLE_UPDATED, _VERSION_CREATED, _TERRITORY_AVAILABILITY_UPDATEDAlternative marketplaces

Creating a webhook in App Store Connect

You need the Account Holder, Admin or App Manager role. In Users and Access, click Integrations, then Webhooks under Additional, and click the add button. Enter a name, the payload URL where you want notifications, and a secret, then select the app and at least one event trigger. You can later edit the name, secret, URL and triggers, but not the app: for another app, create a new webhook.

Managing webhooks through the API

The same setup is available in the App Store Connect API: POST /v1/webhooks creates a configuration, PATCH /v1/webhooks/{id} updates enabled, name, url, secret and eventTypes, GET /v1/apps/{id}/webhooks lists an app’s webhooks and GET /v1/webhooks/{id}/deliveries shows past deliveries. You call it with an API key; see how to create an App Store Connect API key.

Verifying the signature

Apple secures webhooks with an HMAC. App Store Connect hashes each payload body with your secret and sends the result in the x-apple-signature header. On your server, compute an HMAC-SHA256 hex digest of the raw body with the same secret and compare it with the header; reject the request if they differ. Choose a secret that’s hard to guess.

Testing and parsing deliveries

In App Store Connect, open the webhook and click Test: a delivery with the Ping trigger goes to your server and shows in Recent Deliveries. Through the API, POST /v1/webhookPings does the same. Each notification carries a type, such as appStoreVersionAppVersionStateUpdated, attributes such as oldValue, newValue and timestamp, and a relationship to the affected resource, which you then read with the API, for example GET /v1/appStoreVersions/{id}. Background asset events are the exception: they put the resource directly in relationships.instance, without a data object. For purchase and subscription events, use App Store Server Notifications V2 instead; review timing is covered in App Store and Google Play review times.

Where Censuus fits

A webhook tells you the moment your update is live; being found is what brings users to it. Censuus ranks apps by the visits they draw, and adding your app is free on the List my app form. Placement comes from traffic and sponsorship: apps climb on the visits they draw, and a sponsor can pay to rise higher.

Frequently asked questions

Does App Store Connect support webhooks?

Yes. You can create webhooks in Users and Access → Integrations → Webhooks or with the App Store Connect API, and receive POST requests for app review state changes, builds, TestFlight, beta feedback, background assets and alternative distribution.

How many webhooks can an app have?

Up to ten. Each webhook applies to one app.

How do I verify an App Store Connect webhook?

Compute an HMAC-SHA256 hex digest of the raw request body using your webhook secret and compare it with the x-apple-signature header.

Can I get notified when my app is approved?

Yes. APP_STORE_VERSION_APP_VERSION_STATE_UPDATED fires when an App Store version’s state changes, including review states, with the old and new values in the payload.

Who can create webhooks?

Users with the Account Holder, Admin or App Manager role.

Guides for app developers

Put your app in the ranking

Censuus ranks apps by the visits they draw and by sponsorship, no bots. Listing is free; sponsorship raises placement.