GrowthRailDocs

Webhook events

EventWhat it signalsGrowth Rail action
direct.user.createUser signup confirmed by provider.Record signup proof; join to pending SDK attribution claim.
direct.member.createUser signup confirmed by provider.Record signup proof; join to pending SDK attribution claim.

How attribution works

A verified provider event proves the signup happened — but not that the user was referred. Growth Rail completes a referral only when that event joins to the opaque attribution claim previously captured by the SDK on the referring user's device.

Identity rule: Growth Rail joins events to claims using stable IDs and opaque tokens. It never correlates users by email, name, phone number, or billing address.
1

Create the Growth Rail connection

Open Dashboard → Integrations → Auth, choose Stytch, and create a Sandbox or Production connection. Copy the generated webhook endpoint URL — you will paste it into Stytch in the next step.

2

Register the webhook in Stytch

In Stytch Dashboard → Webhooks, add the copied endpoint and subscribe to direct.user.create, direct.member.create.

Return to Growth Rail and save the Stytch/Svix signing secret (whsec_…). Growth Rail encrypts and stores it — the raw value is never returned by the API after saving.

Security: Never commit webhook secrets to source control or log them. If a secret is compromised, rotate it in both Stytch and Growth Rail immediately.
3

Pass attribution data from your app

For Consumer projects, pass user.user_id to Growth Rail. For B2B projects, pass member.member_id. Enable only the event matching your Stytch project model.

ts
// Consumer: user.user_id · B2B: member.member_id
await GrowthRail.initAppUser(stytchUserId);
4

Verify end-to-end in test mode

Create one user through the Stytch SDK/API path used by your product and confirm the direct.user.create or direct.member.create delivery in Growth Rail.

OutcomeMeaning
CompletedSignup proof and SDK attribution token matched. The referral reward has been triggered.
Awaiting attributionThe webhook signature was valid, but the SDK claim has not arrived yet — or the stable user ID did not match a pending claim. The event is held; Growth Rail completes the referral when the claim arrives.
IgnoredThe event was verified but no matching attribution claim exists and the hold window has expired, or the event type is out of scope.
Provider-specific notes
  • Dashboard and SCIM creation use different Stytch event variants and are intentionally not treated as self-service signup proof.
  • Do not mix Consumer user IDs and B2B member IDs within one Growth Rail connection.