Inbound Webhooks (Ingest)
The endpoint a project calls to send a signed payload to an inbound webhook, with every response it can return.
Submit a payload
POST
/api/inbound-webhooks/{id}/submitValidated against the webhook schema. Every field error is returned at once.
Authentication: Project API key (X-API-Key header)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | |
X-MCDI-Signature | header | string | no | t=<unix seconds>,v1=<hex hmac-sha256 of "t.<raw body>"> |
Responses
| Status | Description | Body |
|---|---|---|
201 | Accepted. | |
400 | Bad signature (401) or rate limited (429). | |
403 | Origin not in the allowlist. | |
404 | No such webhook for this project. | |
409 | Signature replayed. | |
410 | Webhook is inactive. | |
422 | Payload failed schema validation. |
Open in Swagger (opens in a new tab)
Source: apps/api/openapi.json.