FusionAuth sends webhooks for events such as a user being created or registered. Point one at a small endpoint of yours that calls isBusinessEmail. FusionAuth also lets you configure how event transactions behave, so a failing webhook can stop the operation. Check FusionAuth’s webhook documentation for which events and settings support that in your version.
The webhook endpoint (Express)
import express from 'express';
const app = express();
app.use(express.json());
async function checkWorkEmail(email) {
try {
const res = await fetch('https://api.isbusinessemail.com/v1/check', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.IBE_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({ email }),
signal: AbortSignal.timeout(2500),
});
return res.ok ? await res.json() : { recommendation: 'allow', failOpen: true };
} catch {
return { recommendation: 'allow', failOpen: true };
}
}
app.post('/webhooks/fusionauth', async (req, res) => {
// Authenticate the webhook first (shared secret header or signature; see FusionAuth docs).
const event = req.body?.event;
const email = event?.user?.email;
if (!email) return res.sendStatus(200);
const verdict = await checkWorkEmail(email);
await saveVerdict(event.user.id, verdict); // your DB, or user.data via the FusionAuth API
// If this webhook is configured to block the transaction, a non-2xx response stops it.
if (verdict.recommendation === 'block') return res.status(422).send('work email required');
return res.sendStatus(200);
});
app.listen(3000);
Blocking vs flagging
- Flag (simplest, safest): always return
200, store the verdict, and let your app restrict accounts withblockorreview. - Block: with a transaction-blocking webhook, return non-2xx on
block. Make sure every failure on our side still returns200, which is whycheckWorkEmailfails open.
Your own sign-up form
If you render your own sign-up page and call FusionAuth’s registration API from your server, check the address first and show the error inline, the friendlier option. See the signup form guide.
Tips
- Store
email_categoryand Microsoft 365 / Google Workspace detection in the user’sdataso your app can route onboarding without another call. - Test with
disposable@test.isbusinessemail.comandm365@test.isbusinessemail.com.
Official docs: FusionAuth documentation (see Webhooks and Events). See also: Response fields.