API Docs / Operations / Webhooks

Webhooks

The tenant's webhooks: HTTPS URLs sent the events they subscribe to (subcontractor, verification, invoice and return events, and webhook.auto_disabled). Each delivery is a POST of the event as JSON, signed with the webhook's secret in X-Webhook-Signature and named in X-Webhook-Event; one that fails is retried with increasing delays, and a webhook whose deliveries keep failing is switched off and its tenant emailed. The secret is returned when the webhook is created and on its single GET. Deliveries are the history: what was sent, how often, and the receiver's answer; a failed one can be sent again.