Skip to main content
WEBHOOK

Authorizations

Authorization
string
header
required

An organization API key. Keys carry a role (read_write or read_only) and may be restricted to a namespace prefix such as acme/*, or to one namespace such as acme/prod/tenant_1. A prefix matches on a / boundary: acme/prod/tenant_1* covers acme/prod/tenant_1 and everything under acme/prod/tenant_1/, never acme/prod/tenant_12.

Headers

webhook-id
string
required

The event's id. A retry, a redelivery or a replay repeats it, so dedupe on it. Also the webhook-id header.

Pattern: ^evt_[0-9a-z]{26}$
webhook-timestamp
integer<int64>
required

When this attempt was sent, in Unix seconds. Reject a request more than 5 minutes off your clock.

webhook-signature
string
required

Space-separated signatures, each v1, and the base64 HMAC-SHA256 of {webhook-id}.{webhook-timestamp}.{body}, keyed by the endpoint's secret: the part after whsec_, base64-decoded. While a rotated secret is still valid there is one signature per secret; accept the request if any of them matches.

Body

application/json
id
string
required

Also the webhook-id header.

Pattern: ^evt_[0-9a-z]{26}$
timestamp
string<date-time>
required

When the event was recorded.

type
any
required
data
object
required

Membership changed in bulk without an event per document. Re-read the members with the subscription's query.

test
boolean

True on every event a test send sends, webhook.test or a sample of a named type. Absent otherwise, and never in the feed.

Response

2XX

Received. Anything else, or no answer within 15 seconds, is retried.