HACK-ATTACK

Register a webhook

How it works

  1. Challenge. We POST {"type":"webhook.verification","data":{"challenge":"…"}} to your URL. Reply 2xx with the challenge as the raw body or as {"challenge":"…"}.
  2. Secret. On success you get a signing secret (whsec_…) and a management token.
  3. Test event. A signed test event follows immediately.
  4. Events. event.published and event.retracted, body {"type","timestamp","data"}.

Signatures follow Standard Webhooks: headers webhook-id, webhook-timestamp, webhook-signature (v1, + base64 HMAC-SHA256 of id.timestamp.body, keyed with the base64-decoded secret after whsec_). Use any Standard Webhooks library to verify. De-duplicate on webhook-id: it is stable across retries.

Retries: about 5 s, 5 min, 30 min, 2 h, 5 h, 10 h, 10 h. After 5 deliveries in a row fail all retries, the endpoint is disabled; re-enable it with POST /v1/webhooks/{id}/enable and your management token.

Only public HTTPS destinations are accepted. Private, loopback and link-local addresses are refused, redirects are not followed, and requests time out after 5 seconds.