Events
You get
post.generation.* events for tracked post generation jobs, including the
ones you start with POST /v1/posts/generate. post.published fires the first time
a post moves to published. Unpublishing and publishing it again won’t send a
second event. We write the event in the same database transaction as the status
change, so every published post has one. GEO scans don’t send events yet, so keep
polling for those.
Subscribe through the API
Use an organization API key with thewebhooks.write scope:
endpoint and a one-time secret. Save the secret somewhere
safe because you won’t see it again. GET /v1/webhooks lists your subscriptions.
DELETE /v1/webhooks/{endpointId} removes one and cancels anything not sent yet. A
request that’s already on its way can still reach the deleted endpoint.
Verify requests
Read the body as raw text before you parse the JSON. Every request has these headers:x-notra-event: the event typex-notra-event-id: a stable event IDx-notra-delivery-id: a stable delivery ID for this endpointx-notra-timestamp: when we signed it, in Unix secondsx-notra-signature:v1,followed by a base64 HMAC-SHA256 signature
whsec_ prefix from your secret, base64-decode the rest and check the
HMAC over this UTF-8 message:
Logs and retries
The delivery table shows the status, response code, attempt count and when each delivery was created. Click a row to see the payload, the destination, the event and delivery IDs, how each attempt went and when the next retry is due. You can retry a failed delivery after a one-minute cooldown. Earlier attempts stay in the history. For API access, usewebhooks.read:
GET /v1/webhooks/deliveries?offset=0&status=allreturns 25 rows andhasMore.GET /v1/webhooks/deliveries/{deliveryId}returns the payload and attempts.POST /v1/webhooks/deliveries/{deliveryId}/retryqueues a failed delivery. This one needswebhooks.write.
Retry-After and goes up
to six hours. Dispatch and recovery run once a minute, so a delivery or retry can
start a little after its scheduled time.
Finished deliveries stay in the history for 30 days. Anything still in progress
stays until it’s done. We don’t store response bodies. Your endpoint has to use a
public HTTPS hostname on port 443.