{
"id": "<string>",
"dataset": "<string>",
"received_at": "2023-11-07T05:31:56Z",
"data": "<unknown>"
}An outbound delivery to a destination
{
"id": "<string>",
"dataset": "<string>",
"received_at": "2023-11-07T05:31:56Z",
"data": "<unknown>"
}Headers
t=,v1=<lowercase hex HMAC-SHA256 of ".">, keyed with the UTF-8 bytes of the whole signing secret (whsec_ included). During a rotation overlap: t=,v1=,v1=. Unchanged since before the Standard Webhooks headers were added.
Standard Webhooks message id: the delivery id (the same value as Hookie-Delivery-Id). Every retry of a delivery repeats it; a replay is a new delivery and carries a new one.
Standard Webhooks timestamp: unix seconds, the same value as Hookie-Signature's t.
^[0-9]+$Standard Webhooks signature: v1,<base64 HMAC-SHA256 of "..">, keyed with the base64-decoded bytes after whsec_ (for a Hookie secret, 36 bytes). During a rotation overlap two entries, space-separated, new first: v1, v1,. Omitted, with webhook-id and webhook-timestamp, only for a secret that is not valid base64, which Hookie never mints.
The record id: the same on every retry and replay. Dedupe on this.
This delivery's id (the same value as webhook-id).
The record id, for receivers that dedupe on this header.
How many times this event has passed through Hookie, plus one. Hookie refuses an event whose hop has reached 8 (508); a relay that forwards into Hookie should pass it on.
^[0-9]+$Body
The body of every outbound delivery. Always this envelope; the record's payload is under data. Verify signatures over the raw bytes as received, never a re-serialisation.
Response
Delivered.