Skip to content
Documentation menu

Webhooks

Signed, at-least-once notifications for completed requests, jobs, deposits and low balances.

Events

  • request.completed
  • job.completed
  • job.failed
  • deposit.credited
  • balance.low
  • webhook.test

Creating an endpoint

text
POST /v1/webhooks   { url, description?, events[] }  → WebhookRecord + secret (shown once)
GET  /v1/webhooks
DELETE /v1/webhooks/{id}
GET  /v1/webhooks/{id}/deliveries

Destinations must be public HTTPS URLs; private networks, metadata addresses and redirects are rejected.

Verifying signatures

Each delivery includes a delivery ID, a timestamp and an HMAC-SHA256 signature over the timestamp and body using the endpoint secret. Reject deliveries whose timestamp is outside your replay window and deduplicate by delivery ID.

At-least-once

Deliveries retry with backoff and are dead-lettered after repeated failures. Make your handler idempotent on the delivery ID.

The dashboard shows delivery history per endpoint and can send a test event.