Webhooks
The tenant's webhooks: HTTPS URLs sent the events they subscribe to (subcontractor, verification, invoice and return events, and webhook.auto_disabled). Each delivery is a POST of the event as JSON, signed with the webhook's secret in X-Webhook-Signature and named in X-Webhook-Event; one that fails is retried with increasing delays, and a webhook whose deliveries keep failing is switched off and its tenant emailed. The secret is returned when the webhook is created and on its single GET. Deliveries are the history: what was sent, how often, and the receiver's answer; a failed one can be sent again.
-
GET List WebhooksThe tenant's webhooks, without their secrets. Filter with enabled; sortBy Name, CreatedDate or Enabled./tenants/{tenant}/webhooks
-
POST Create WebhookAdds a webhook and generates its secret. Every delivery carries X-Webhook-Signature (t={unix time},v1={hex HMAC-SHA256 of "{t}.{body}" with the secret.../tenants/{tenant}/webhooks
-
GET Get WebhookOne webhook, with the secret its deliveries are signed with./tenants/{tenant}/webhooks/{webhook}
-
PUT Update WebhookReplaces the webhook's name, URL, enabled flag and events; the secret is kept. Setting enabled switches a webhook back on after it was switched off fo.../tenants/{tenant}/webhooks/{webhook}
-
DELETE Delete WebhookDeletes the webhook and its delivery history. To keep the history, disable the webhook instead./tenants/{tenant}/webhooks/{webhook}
-
POST Test WebhookQueues a test.webhook delivery to an enabled webhook and returns it, still pending: read the delivery to see how the receiver answered. A disabled web.../tenants/{tenant}/webhooks/{webhook}/test
-
GET List Webhook DeliveriesWhat was sent to the tenant's webhooks, newest first, without the payloads. Filter by webhook, status, event and the dates the events happened between.../tenants/{tenant}/webhooks/deliveries
-
GET Get Webhook DeliveryOne delivery, with the payload that was sent and what the receiver answered on the last attempt./tenants/{tenant}/webhooks/deliveries/{delivery}
-
POST Retry Webhook DeliverySends a failed delivery once more. Refused (400) unless it failed, or when its webhook is disabled./tenants/{tenant}/webhooks/deliveries/{delivery}/retry