Skip to main content
WEBHOOK

Headers

Hookie-Signature
string
required

t=,v1=<lowercase hex HMAC-SHA256 of ".">, keyed with the UTF-8 bytes of the whole signing secret (whsec_ included). During a rotation overlap: t=,v1=,v1=. Unchanged since before the Standard Webhooks headers were added.

webhook-id
string
required

Standard Webhooks message id: the delivery id (the same value as Hookie-Delivery-Id). Every retry of a delivery repeats it; a replay is a new delivery and carries a new one.

webhook-timestamp
string
required

Standard Webhooks timestamp: unix seconds, the same value as Hookie-Signature's t.

Pattern: ^[0-9]+$
webhook-signature
string
required

Standard Webhooks signature: v1,<base64 HMAC-SHA256 of "..">, keyed with the base64-decoded bytes after whsec_ (for a Hookie secret, 36 bytes). During a rotation overlap two entries, space-separated, new first: v1, v1,. Omitted, with webhook-id and webhook-timestamp, only for a secret that is not valid base64, which Hookie never mints.

Hookie-Event-Id
string
required

The record id: the same on every retry and replay. Dedupe on this.

Hookie-Delivery-Id
string
required

This delivery's id (the same value as webhook-id).

Idempotency-Key
string
required

The record id, for receivers that dedupe on this header.

Hookie-Hop
string
required

How many times this event has passed through Hookie, plus one. Hookie refuses an event whose hop has reached 8 (508); a relay that forwards into Hookie should pass it on.

Pattern: ^[0-9]+$

Body

application/json

The body of every outbound delivery. Always this envelope; the record's payload is under data. Verify signatures over the raw bytes as received, never a re-serialisation.

id
string
required

The record (event) id. The same on every retry and replay of it.

dataset
string
required
received_at
string<date-time>
required
data
any
required

The record's payload, as routed.

Response

Delivered.