Skip to main content

Webhooks

Register endpoints (scope webhooks) to receive events as they happen.

Events

Delivery & verification

Each delivery is HMAC-signed with a per-endpoint secret shown once at registration. Verify the signature before trusting the payload.
Registration URLs must be HTTPS and are SSRF-screened. An endpoint that fails delivery repeatedly is auto-disabled.

Managing endpoints

WEBHOOK_ENC_KEY must be configured on the backend for webhook creation to succeed — per-endpoint secrets are encrypted at rest.