Skip to content

A test event sent on request (`POST /v1/webhook-endpoints/{endpointId}/test`)

POST
webhook-id
required
string

The event id; the same on every retry. Deduplicate on it.

webhook-timestamp
required
string
/^[0-9]+$/

Unix seconds when the request was signed. Reject requests far from your clock.

webhook-signature
required
string

v1,<base64 HMAC-SHA256 of "{webhook-id}.{webhook-timestamp}.{body}"> under the endpoint’s secret; space-separated when two secrets sign during a rotation.

Media typeapplication/json
object
id
required
string
type
required
string
Allowed value: webhook.test
createdAt
required
string format: date-time
data
required
object
endpointId
required
string

Received. Any other answer, or none within 10 seconds, is retried.