Skip to content

Models: W

  • delivery_id: str (deliveryId on the wire)
  • endpoint_id: str (endpointId on the wire)
  • event: kindgi.client.RunFinishedEvent | kindgi.client.WebhookTestEvent
  • status: Literal['pending', 'delivered', 'failed']
  • attempts: int
  • next_attempt_at: AwareDatetime | None (nextAttemptAt on the wire)
  • last_attempt_at: AwareDatetime | None (lastAttemptAt on the wire)
  • last_response_status: int | None (lastResponseStatus on the wire)
  • last_error: str | None (lastError on the wire)
  • created_at: AwareDatetime (createdAt on the wire)
  • delivered_at: AwareDatetime | None (deliveredAt on the wire)
  • data: list[kindgi.client.WebhookDelivery]
  • next_cursor: str | None (nextCursor on the wire) (optional)
  • has_more: bool (hasMore on the wire)
  • endpoint_id: str (endpointId on the wire)
  • url: AnyUrl
  • events: list[Literal['run.finished']]
  • filter: kindgi.client.WebhookEndpointFilter
  • description: str | None
  • secret_ref: kindgi.client.WebhookSecretRef (secretRef on the wire)
  • created_at: AwareDatetime (createdAt on the wire)
  • updated_at: AwareDatetime (updatedAt on the wire)
  • data: list[kindgi.client.WebhookEndpoint]
  • next_cursor: str | None (nextCursor on the wire) (optional)
  • has_more: bool (hasMore on the wire)

Which events reach the endpoint. Every field narrows; absent fields do not. run.finished is sent for top-level runs only.

  • project_id: str | None (projectId on the wire) (optional)
  • flow_ids: list[kindgi.client.FlowId] | None (flowIds on the wire) (optional)
  • include_dry_runs: bool | None (includeDryRuns on the wire) (optional)
  • endpoint_id: str (endpointId on the wire)
  • unregistered: bool

A secret by name in the deployment's secrets store, resolved at tenant scope (the same shape as a provider's secret_ref). The value is whsec_ + base64 of at least 24 random bytes (or that base64 alone); the store keeps it, the endpoint keeps only this reference.

  • env_name: str (envName on the wire)
  • name: str
  • id: str
  • type: Literal['webhook.test']
  • created_at: AwareDatetime (createdAt on the wire)
  • data: kindgi.client.Data1
  • data: list[kindgi.client.WebhookTriggerRecord]
  • next_cursor: str | None (nextCursor on the wire) (optional)
  • has_more: bool (hasMore on the wire)
  • trigger_id: str (triggerId on the wire)
  • webhook_id: str (webhookId on the wire)
  • flow_id: str (flowId on the wire)
  • flow_version: str (flowVersion on the wire)
  • input: Any | None (optional)
  • hmac_secret_name: str (hmacSecretName on the wire)
  • label: str | None
  • status: Literal['active', 'paused']
  • last_fired_at: AwareDatetime | None (lastFiredAt on the wire)
  • created_at: AwareDatetime (createdAt on the wire)
  • updated_at: AwareDatetime (updatedAt on the wire)
  • trigger_id: str (triggerId on the wire)
  • unregistered: bool

Introspection of the caller's current authentication context. Always carries tenantId and scopes (empty for static bearer tokens), plus userId when the token carries one; session-token callers additionally see sessionId, providerId, and expiresAt. user is the caller's directory record, present when the deployment wires an identity directory and it knows the userId. reviewerRole is set when the token carries a reviewer role — clients can use it to gate reviewer-only UI (the approvals surface) without a second round trip.

  • tenant_id: uuid.UUID (tenantId on the wire)
  • user_id: str | None (userId on the wire) (optional)
  • session_id: str | None (sessionId on the wire) (optional)
  • provider_id: str | None (providerId on the wire) (optional)
  • scopes: list[str]
  • expires_at: AwareDatetime | None (expiresAt on the wire) (optional)
  • reviewer_role: Optional[Literal['standard', 'senior', 'admin']] (reviewerRole on the wire) (optional)
  • user: kindgi.client.UserRecord | None (optional)
  • error: kindgi.client.Error
  • reason: str

Write a fact. type selects the retrieval-policy (which indexes populate); scope.tenantId MUST match the caller's tenant. Optional retention overrides tenant defaults; optional contentHash is a caller-supplied idempotence hint (runtime computes its own hash regardless).

  • type: str
  • scope: kindgi.client.FactScope
  • content: Any
  • retention: kindgi.client.Retention | None (optional)
  • content_hash: str | None (contentHash on the wire) (optional)