Tunploy
APIReferenceWebhooks

An event happened

Posted to each webhook that subscribes to the event's kind. Check X-Tunploy-Signature before trusting the body: t=<unix time>,v1=<hex>, where v1 is HMAC-SHA256 over <t>.<raw body> keyed with the webhook's secret. Turn away timestamps more than a few minutes old.

Answer with a 2xx within 10 seconds. Anything else, a timeout or a redirect is tried again after 1 and 5 minutes, 30 minutes, 2, 6 and 12 hours, then given up. Deliveries can arrive out of order and more than once: use the event ID or X-Tunploy-Delivery to skip repeats.

Header Parameters

X-Tunploy-Event*string

The event kind, or ping.

X-Tunploy-Delivery*string
X-Tunploy-Signature*string

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

Example Requests

POST/event