POST /v1/webhooks. Registrations apply to matching jobs across your account. Up to 10 active endpoints are allowed, using HTTPS on port 443 and publicly reachable addresses. Redirects are not followed.
Supported events are prompt.completed, prompt.failed, prompt.cancelled, prompt.paused, conversion.completed, conversion.failed, and conversion.cancelled.
signing_secret securely. It is returned on creation and idempotent replay, not on list responses. The TypeScript equivalent is revise.webhooks.create(body, { idempotencyKey }).
Notification payload
Notifications contain a job reference, not document bytes or the full receipt:data.conversion_id instead of data.prompt_id. A paused prompt can have content_expires_at: null. Retrieve the receipt with your API key, then download any artifacts. A completion event means succeeded; still inspect prompt partial-completion fields.
Verify signatures
Deliveries includewebhook-id, webhook-timestamp (Unix seconds), and webhook-signature. To verify a delivery:
- Remove
whsec_from the signing secret and base64-decode the remainder. - Use the raw request body. Don’t parse and reserialize the JSON before verifying.
- Compute HMAC-SHA256 over
webhook-id + "." + webhook-timestamp + "." + rawBody. - Base64-encode the digest and compare the
v1,signature using a constant-time comparison. - Check timestamp freshness and deduplicate accepted notification IDs.
Acknowledgements and retries
Return 2xx within 30 seconds after durably accepting the notification. Non-2xx responses and network failures trigger retries. Deliveries can be duplicated or arrive out of order. Retrieve the job to confirm its current state. Automatic delivery makes up to 11 attempts within 24 hours. Retry delays start at 10 seconds and grow to 8 hours, with jitter. Exact delivery timing is not guaranteed. List delivery history withGET /v1/webhooks/{id}/deliveries. History lasts 30 days. exhausted deliveries can be manually retried up to three times within seven days of creation, each with its own idempotency key. Manual retries do not restore expired job content.
Deleting a webhook disables it and cancels pending deliveries. An in-flight delivery may already have reached your receiver. There is no update endpoint; register a replacement if the URL or event subscriptions change.
Delete content after acknowledgement
Set the following on a prompt or conversion to remove its retained content after delivery:delete_on_acknowledgement: true.
Download and durably store all required output before returning 2xx. If that cannot finish within the delivery timeout, use ordinary retention and explicitly delete content after background processing. Acknowledgement does not extend the 24-hour content deadline.