Webhook Events
Your endpoint receives this POST. Respond 2xx to acknowledge; non-2xx (and 3xx) are retried with backoff.
Every delivery POSTs this envelope. Verify the X-CA-Signature: sha256=<hex> header — an HMAC-SHA256 of the raw request body keyed by your endpoint's signing secret — before trusting it.
Delivery id (also in the X-CA-Delivery-Id header); stable across retries — use it to dedupe.
Acknowledged.
No content
Payload
Your endpoint receives this POST. Respond 2xx to acknowledge; non-2xx (and 3xx) are retried with backoff.
Every delivery POSTs this envelope. Verify the X-CA-Signature: sha256=<hex> header — an HMAC-SHA256 of the raw request body keyed by your endpoint's signing secret — before trusting it.
Delivery id (also in the X-CA-Delivery-Id header); stable across retries — use it to dedupe.
Acknowledged.
No content
Payload
Your endpoint receives this POST. Respond 2xx to acknowledge; non-2xx (and 3xx) are retried with backoff.
Every delivery POSTs this envelope. Verify the X-CA-Signature: sha256=<hex> header — an HMAC-SHA256 of the raw request body keyed by your endpoint's signing secret — before trusting it.
Delivery id (also in the X-CA-Delivery-Id header); stable across retries — use it to dedupe.
Acknowledged.
No content
Payload
Your endpoint receives this POST. Respond 2xx to acknowledge; non-2xx (and 3xx) are retried with backoff.
Every delivery POSTs this envelope. Verify the X-CA-Signature: sha256=<hex> header — an HMAC-SHA256 of the raw request body keyed by your endpoint's signing secret — before trusting it.
Delivery id (also in the X-CA-Delivery-Id header); stable across retries — use it to dedupe.
Acknowledged.
No content
Payload
Your endpoint receives this POST. Respond 2xx to acknowledge; non-2xx (and 3xx) are retried with backoff.
Every delivery POSTs this envelope. Verify the X-CA-Signature: sha256=<hex> header — an HMAC-SHA256 of the raw request body keyed by your endpoint's signing secret — before trusting it.
Delivery id (also in the X-CA-Delivery-Id header); stable across retries — use it to dedupe.
Acknowledged.
No content
Payload
Your endpoint receives this POST. Respond 2xx to acknowledge; non-2xx (and 3xx) are retried with backoff.
Every delivery POSTs this envelope. Verify the X-CA-Signature: sha256=<hex> header — an HMAC-SHA256 of the raw request body keyed by your endpoint's signing secret — before trusting it.
Delivery id (also in the X-CA-Delivery-Id header); stable across retries — use it to dedupe.
Acknowledged.
No content
Payload
Last updated
Was this helpful?
