Webhooktest
Sent by a test send without a type, marked test: true.
Authorizations
An organization API key. Keys carry a role (read_write or
read_only) and may be restricted to a namespace prefix such as
acme/*, or to one namespace such as acme/prod/tenant_1. A prefix
matches on a / boundary: acme/prod/tenant_1* covers
acme/prod/tenant_1 and everything under acme/prod/tenant_1/,
never acme/prod/tenant_12.
Headers
The event's id. A retry, a redelivery or a replay repeats it, so dedupe on it.
Also the webhook-id header.
^evt_[0-9a-z]{26}$When this attempt was sent, in Unix seconds. Reject a request more than 5 minutes off your clock.
Space-separated signatures, each v1, and the base64 HMAC-SHA256 of
{webhook-id}.{webhook-timestamp}.{body}, keyed by the endpoint's
secret: the part after whsec_, base64-decoded. While a rotated
secret is still valid there is one signature per secret; accept the
request if any of them matches.
Body
Also the webhook-id header.
^evt_[0-9a-z]{26}$When the event was recorded.
True on every event a test send sends, webhook.test or a sample of a named type. Absent otherwise, and never in the feed.
Response
Received. Anything else, or no answer within 15 seconds, is retried.