HACK-ATTACK
Register a webhook
Save these now. They are shown once.
How it works
- Challenge. We POST
{"type":"webhook.verification","data":{"challenge":"…"}}to your URL. Reply 2xx with the challenge as the raw body or as{"challenge":"…"}. - Secret. On success you get a signing secret (
whsec_…) and a management token. - Test event. A signed
testevent follows immediately. - Events.
event.publishedandevent.retracted, body{"type","timestamp","data"}.
Signatures follow Standard Webhooks: headers webhook-id, webhook-timestamp, webhook-signature (v1, + base64 HMAC-SHA256 of id.timestamp.body, keyed with the base64-decoded secret after whsec_). Use any Standard Webhooks library to verify. De-duplicate on webhook-id: it is stable across retries.
Retries: about 5 s, 5 min, 30 min, 2 h, 5 h, 10 h, 10 h. After 5 deliveries in a row fail all retries, the endpoint is disabled; re-enable it with POST /v1/webhooks/{id}/enable and your management token.
Only public HTTPS destinations are accepted. Private, loopback and link-local addresses are refused, redirects are not followed, and requests time out after 5 seconds.