subscription.entered
A document started matching a subscription. It carries the included attributes and answers, as the get returns them.
Authorizations
An organization API key. Keys carry a role (read_write or
read_only) and may be restricted to a namespace prefix such as
acme/*, or to one namespace such as acme/prod/tenant_1. A prefix
matches on a / boundary: acme/prod/tenant_1* covers
acme/prod/tenant_1 and everything under acme/prod/tenant_1/,
never acme/prod/tenant_12.
Headers
The event's id. A retry, a redelivery or a replay repeats it, so dedupe on it.
Also the webhook-id header.
^evt_[0-9a-z]{26}$When this attempt was sent, in Unix seconds. Reject a request more than 5 minutes off your clock.
Space-separated signatures, each v1, and the base64 HMAC-SHA256 of
{webhook-id}.{webhook-timestamp}.{body}, keyed by the endpoint's
secret: the part after whsec_, base64-decoded. While a rotated
secret is still valid there is one signature per secret; accept the
request if any of them matches.
Body
Also the webhook-id header.
^evt_[0-9a-z]{26}$When the event was recorded.
A document that started matching (subscription.entered), and the
body of subscription.exited. It carries the included attributes
and answers, and those the filter reads, as the get returns them,
never state. The answers the filter reads have settled: fresh,
or stale when nothing is coming to refresh them (as for a
periodic or manual judgment), or absent where the filter tests
absence. An answer named only in include is sent as it stands,
pending included: check its freshness to act only on fresh
answers. When the whole event, as the request body, would
pass 63 KB they are dropped and truncated is true: follow url.
So no body passes 64 KB.
True on every event a test send sends, webhook.test or a sample of a named type. Absent otherwise, and never in the feed.
Response
Received. Anything else, or no answer within 15 seconds, is retried.