Source type
AWS SNS Source
AWS SNS sources receive HTTP/S topic notifications, verify SNS RSA signatures, and can answer subscription confirmations.
When to use this source type
Choose the AWS_SNS source type when AWS SNS is the system sending webhook requests into FastHook. The source type keeps sender-specific setup close to the source: accepted methods, verification headers, challenge handling, and the exact credential fields are documented together so operators do not need to translate a generic HMAC form into a provider-specific contract.
FastHook verifies the source before accepted traffic is queued. A valid request is stored with verified: true, then connections route it to destinations. A bad signature, wrong token, or missing provider header is rejected as SOURCE_AUTH_FAILED. A method outside the allowed set is rejected as SOURCE_METHOD_NOT_ALLOWED.
FastHook configuration
In the dashboard, create a source, set Source Type to AWS SNS, keep Authenticate enabled when verification is required, and fill the fields below.
Source TypeAWS_SNS
Allowed methodsPOST, PUT, PATCH, DELETE
AuthenticationProvider signature
Optional Topic ARNCopy this value from AWS SNS and store it on the FastHook source.
Optional certificate/public key through APICopy this value from AWS SNS and store it on the FastHook source.
{
"type": "AWS_SNS",
"config": {
"auth_type": "PROVIDER_SIGNATURE",
"auth": {
"provider": "AWS_SNS",
"topic_arn": "optional-topic-arn"
},
"allowed_http_methods": ["POST","PUT","PATCH","DELETE"]
}
}curl -X POST "https://api.fasthook.io/v1/sources" \
-H "Authorization: Bearer $FASTHOOK_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "AWS SNS production",
"type": "AWS_SNS",
"config": {
"auth_type": "PROVIDER_SIGNATURE",
"auth": {
"provider": "AWS_SNS",
"topic_arn": "optional-topic-arn"
},
"allowed_http_methods": [
"POST",
"PUT",
"PATCH",
"DELETE"
]
}
}'Subscription confirmation before notifications
Some providers do not send normal event payloads first. They validate the callback URL or subscription contract before delivery starts, so keep the methods listed below enabled during setup.
- AWS SNS sends a SubscriptionConfirmation message before normal Notification messages.
- FastHook verifies the SNS message signature and can auto-confirm the subscription when configured.
- After confirmation, SNS sends signed Notification messages to the same Source URL.
HTTP methods
This source accepts only the methods listed below. Keep the set narrow so provider mistakes and accidental test calls are visible as rejected requests instead of being silently accepted.
Special response: Subscription confirmation payloads can be confirmed automatically when API config enables it.
Headers and verification
FastHook verifies the provider-specific values below before the request is accepted. The comparison is done against the raw inbound request body or the exact provider-specific signing input described here.
SignatureSNS message signature field in the JSON body.
SigningCertURLSNS certificate URL used to fetch the public key when not configured inline.
SignatureVersionSelects SHA-1 or SHA-256 RSA verification.
SubscribeURLUsed for subscription confirmation when auto-confirm is enabled by API config.
FastHook builds the canonical SNS string and verifies the RSA PKCS#1 signature using the SNS certificate or configured public key.
Provider setup checklist
- Subscribe the FastHook Source URL as an HTTP/S endpoint for the SNS topic.
- Optionally configure Topic ARN so FastHook rejects messages from unexpected topics.
- Use the API for advanced options such as inline certificate or auto-confirm subscription.
- Open Amazon SNS HTTP/S subscriber documentation when you need the provider's event list, dashboard steps, or retry policy.
Supported event types and payload shape
FastHook stores the original AWS SNS request before routing so filters, transformations, retries, and replay decisions can use the same provider evidence. Use stable headers and payload fields for routing rather than relying on receiver-side logs alone.
- AWS SNS webhook events should be routed by stable provider headers, event type fields, object ids, or payload paths that do not change between retries.
- Use provider delivery ids or business object ids as idempotency inputs before retrying or replaying traffic.
Troubleshooting
- No request appears: the provider is not calling the generated FastHook Source URL, the source URL was copied before saving, or the provider has not completed its setup validation.
- 405 method rejected: the provider sent a method outside
POST, PUT, PATCH, DELETE. Edit the source only if the provider documentation says that method is expected. - 401 source auth failed: check the configured FastHook field, the provider signing secret, and the header names listed on this page.
- Signature mismatch: make sure the provider signs the same public Source URL it calls and that no proxy, parser, or manual resend changed the raw request body before FastHook received it.
AWS SNS source FAQ
What should I inspect first when AWS SNS delivery fails?
Start with FastHook Requests to confirm the provider reached the source and passed verification. Then open the routed Event and destination Attempts when ingress succeeded but downstream delivery failed.
Can I retry or replay AWS SNS webhook traffic?
Yes, after the receiver or route is fixed. Confirm idempotency with provider delivery ids or business object ids before replaying traffic that can create external side effects.