curl --request GET \
--url https://app.hookie.ai/portal/api/examples \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.hookie.ai/portal/api/examples', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/portal/api/examples"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"examples": [
{
"dataset": "orders",
"source": "recent_record_redacted",
"payload": {
"id": "<event id>",
"dataset": "orders",
"received_at": "<ISO 8601 timestamp>",
"data": {
"order_id": "<string>",
"amount": 0
}
}
}
],
"signature": {
"header": "Hookie-Signature",
"format": "t=<unix seconds>,v1=<hex HMAC-SHA256>",
"signed_content": "<t>.<raw request body>",
"note": "During a secret rotation the header carries one v1 per live secret for 24 hours; accept the request when any v1 matches."
},
"standard_webhooks": {
"headers": [
"webhook-id",
"webhook-timestamp",
"webhook-signature"
],
"format": "v1,<base64 HMAC-SHA256>",
"signed_content": "<webhook-id>.<webhook-timestamp>.<raw request body>",
"secret": "Pass your whsec_ signing secret to the library exactly as shown. Do not strip the prefix or decode it: the library does both.",
"libraries": "https://github.com/standard-webhooks/standard-webhooks/tree/main/libraries",
"spec": "https://www.standardwebhooks.com",
"note": "webhook-id is the delivery id, so a retry repeats it. During a secret rotation webhook-signature carries one space-separated v1 per live secret for 24 hours; a library accepts the request when any matches."
},
"headers": [
"Hookie-Signature",
"Hookie-Event-Id",
"Hookie-Delivery-Id",
"Idempotency-Key",
"webhook-id",
"webhook-timestamp",
"webhook-signature"
]
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Example payloads for each exposed event type, and how to verify a delivery (both signature schemes)
For each dataset the portal exposes (#198, PORT-11): the JSON envelope Hookie POSTs, around the shape of the dataset’s latest record with every value replaced (strings "<string>", numbers 0, booleans false, arrays one element, at most 6 levels and 50 keys). A portal’s customers share its datasets, so no value from a record is ever returned — only field names. A dataset with no record yet shows the envelope with empty data. The response documents both signatures every delivery carries over one timestamp: signature (Hookie-Signature) and, since #245, standard_webhooks (the Standard Webhooks webhook-id / webhook-timestamp / webhook-signature set added by #192, DLV-12), which a receiver can check with an official standardwebhooks library by passing the whsec_ signing secret as is.
curl --request GET \
--url https://app.hookie.ai/portal/api/examples \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.hookie.ai/portal/api/examples', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/portal/api/examples"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"examples": [
{
"dataset": "orders",
"source": "recent_record_redacted",
"payload": {
"id": "<event id>",
"dataset": "orders",
"received_at": "<ISO 8601 timestamp>",
"data": {
"order_id": "<string>",
"amount": 0
}
}
}
],
"signature": {
"header": "Hookie-Signature",
"format": "t=<unix seconds>,v1=<hex HMAC-SHA256>",
"signed_content": "<t>.<raw request body>",
"note": "During a secret rotation the header carries one v1 per live secret for 24 hours; accept the request when any v1 matches."
},
"standard_webhooks": {
"headers": [
"webhook-id",
"webhook-timestamp",
"webhook-signature"
],
"format": "v1,<base64 HMAC-SHA256>",
"signed_content": "<webhook-id>.<webhook-timestamp>.<raw request body>",
"secret": "Pass your whsec_ signing secret to the library exactly as shown. Do not strip the prefix or decode it: the library does both.",
"libraries": "https://github.com/standard-webhooks/standard-webhooks/tree/main/libraries",
"spec": "https://www.standardwebhooks.com",
"note": "webhook-id is the delivery id, so a retry repeats it. During a secret rotation webhook-signature carries one space-separated v1 per live secret for 24 hours; a library accepts the request when any matches."
},
"headers": [
"Hookie-Signature",
"Hookie-Event-Id",
"Hookie-Delivery-Id",
"Idempotency-Key",
"webhook-id",
"webhook-timestamp",
"webhook-signature"
]
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Authorizations
A hpt_… customer portal token, as Authorization: Bearer. Stored hashed and looked up by its full SHA-256 hash; shown once at issue. The query string (?token=) is not accepted: a token there ends up in request logs and traces. A browser page trades the token for a portalSession cookie with POST /portal/api/session.
Response
Examples and the signature scheme.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
The Standard Webhooks signature (https://www.standardwebhooks.com) every delivery also carries (DLV-12). webhook-id is the delivery id, so a retry repeats it; during a secret rotation webhook-signature carries one space-separated v1, value per live secret.
Show child attributes
Show child attributes
Every header a delivery carries: Hookie's own and the Standard Webhooks set.