Skip to main content

Inbound Webhooks (Ingest)

The endpoint a project calls to send a signed payload to an inbound webhook, with every response it can return.

Submit a payload

POST/api/inbound-webhooks/{id}/submit

Validated against the webhook schema. Every field error is returned at once.

Authentication: Project API key (X-API-Key header)

Parameters

NameInTypeRequiredDescription
idpathstringyes
X-MCDI-Signatureheaderstringnot=<unix seconds>,v1=<hex hmac-sha256 of "t.<raw body>">

Responses

StatusDescriptionBody
201Accepted.
400Bad signature (401) or rate limited (429).
403Origin not in the allowlist.
404No such webhook for this project.
409Signature replayed.
410Webhook is inactive.
422Payload failed schema validation.

Open in Swagger (opens in a new tab)

Source: apps/api/openapi.json.