Skip to main content
GET
Example payloads for each exposed event type, and how to verify a delivery (both signature schemes)

Authorizations

Authorization
string
header
required

A hpt_… customer portal token, as Authorization: Bearer. Stored hashed and looked up by its full SHA-256 hash; shown once at issue. The query string (?token=) is not accepted: a token there ends up in request logs and traces. A browser page trades the token for a portalSession cookie with POST /portal/api/session.

Response

Examples and the signature scheme.

examples
object[]
required
signature
object
required
standard_webhooks
object
required

The Standard Webhooks signature (https://www.standardwebhooks.com) every delivery also carries (DLV-12). webhook-id is the delivery id, so a retry repeats it; during a secret rotation webhook-signature carries one space-separated v1, value per live secret.

headers
string[]
required

Every header a delivery carries: Hookie's own and the Standard Webhooks set.