What does the RevenueDot webhook event PRODUCT_CHANGE mean?

The RevenueDot webhook event PRODUCT_CHANGE means a customer switched a subscription to another product, now or at the next renewal.

Quick facts#

Event PRODUCT_CHANGE
Where RevenueDot webhook (event.type), RevenueCat's webhook format
Sent to Every enabled webhook whose filters match
Fields that are specific to it new_product_id
What it means The customer changed product: an upgrade now, or a downgrade or crossgrade scheduled for the next renewal. product_id is the old product.

When it is sent#

  • An upgrade takes effect at once. The event names the old product in product_id and the new one in new_product_id.
  • A downgrade or crossgrade is announced when it is scheduled, and takes effect at the next renewal.
  • A scheduled switch reaching its renewal is only a RENEWAL, because it was announced before.

What your server should do#

  1. For an upgrade, switch the entitlement to new_product_id now.
  2. For a scheduled change, keep the current product and plan the switch for the renewal.
  3. Do not treat the old product's end as a cancellation: no CANCELLATION or EXPIRATION is sent for it.
  4. Deduplicate on event.id: deliveries can repeat, because anything but HTTP 200 is retried after 5, 10, 20, 40 and 80 minutes.

Example#

JavaScript
import { createHmac, timingSafeEqual } from "node:crypto";

// X-RevenueCat-Webhook-Signature: t=<unix seconds>,v1=<hex HMAC-SHA256 of "<t>.<raw body>">
function verify(rawBody, header, secret, toleranceSeconds = 300) {
  const m = /^t=(\d+),v1=([0-9a-f]{64})$/.exec(header ?? "");
  if (!m || Math.abs(Date.now() / 1000 - Number(m[1])) > toleranceSeconds) return false;
  const expected = createHmac("sha256", secret).update(`${m[1]}.${rawBody}`).digest();
  return timingSafeEqual(expected, Buffer.from(m[2], "hex"));
}

// Sign a sample delivery the way RevenueDot does, then handle it.
const secret = "whsec_test_secret";
const rawBody = JSON.stringify({ api_version: "1.0", event: {"id":"66339910-3BFF-49F4-B873-D1283D673DE2","type":"PRODUCT_CHANGE","app_user_id":"user_1","product_id":"pro_monthly","new_product_id":"pro_annual"} });
const t = Math.floor(Date.now() / 1000);
const header = `t=${t},v1=${createHmac("sha256", secret).update(`${t}.${rawBody}`).digest("hex")}`;

const seen = new Set(); // use a database table in production

function handle(rawBody, header) {
  if (!verify(rawBody, header, secret)) return "401 bad signature";
  const { event } = JSON.parse(rawBody);
  if (seen.has(event.id)) return "200 duplicate";
  seen.add(event.id);
  if (event.type !== "PRODUCT_CHANGE") return "200 ignored";
  return "move " + event.app_user_id + " from " + event.product_id + " to " + event.new_product_id;
}

console.log(handle(rawBody, header));

Run-checked: npm run check:snippets runs this snippet with Node and compares its output with from pro_monthly to pro_annual (checked 2026-10-03).

How RevenueDot produces it#

diffSubscription returns PRODUCT_CHANGE when the product on the chain changes without having been announced (fromProduct becomes product_id), and when a different autoRenewProductId appears for the next renewal.

Source#

Checked: 2026-10-03

Edit this page on GitHub ↗ View as Markdown Last updated