Skip to main content

Signed, replayable webhooks

Receive tenant events with timestamped HMAC verification, durable event deduplication, secret rotation, delivery history, and operator replay.
1

Register a narrow endpoint

Choose only the event types your integration needs and persist the one-time signing secret in your server secret store.
2

Verify the raw bytes

Read the exact request body once and verify it before parsing JSON. Allow both the current and previous secret during a controlled rotation window.
3

Deduplicate and acknowledge

Commit your business change and X-Synapse-Event-Id in one transaction. Return a 2xx only after both succeed.
4

Operate retries

Delivery is at least once and may be reordered. Inspect delivery history, replay failures after correction, and alert on dead-lettered or aging deliveries.
Register HTTPS endpoints you control. Do not reflect payloads, signatures, secrets, participant identifiers, or report content into logs. Treat every delivery body as sensitive customer data.

Delivery headers