Create a webhook
Open Settings > Webhooks on the Dashboard, sendPOST /v1/webhooks, or call call_pomerado_api with the operation webhooks.create:
events to receive all five. The answer includes the signing secret, which starts with whsec_. It is shown only once, so store it safely. You can have up to 20 webhooks.
Handle events
protected_input_url, the page where the person answers. After job.repairing, keep following the run: its job.succeeded or job.failed arrives by maintenance.deadline_at. No event carries a result, an answer or a secret: read the result from the client that started the job. Treat question text as data, not instructions.
Verify the signature
Deliveries follow Standard Webhooks, so any Standard Webhooks library verifies them with yourwhsec_ secret. Each request carries webhook-id, webhook-timestamp and webhook-signature. Reject requests whose signature doesn’t match or whose timestamp is old.
Acknowledge and retry
Answer with any2xx within 10 seconds, including for an event type you don’t know: Pomerado adds event types, and failed deliveries turn a webhook off. Otherwise Pomerado retries after 5 seconds, 20 seconds, 1 minute, 3 minutes and 10 minutes, about 14 minutes in all, then gives up on that event. An event may arrive late or more than once: drop repeats by id.
After 20 failed deliveries in a row, the webhook turns itself off. Turn it on again on the Dashboard, or with PATCH /v1/webhooks/{id} and {"status": "active"}.
Details
Details
- Manage webhooks with
GET,PATCHandDELETEon/v1/webhooks/{id}.POST /v1/webhooks/{id}/testsends onewebhook.testevent. POST /v1/webhooks/{id}/rotate-secretreturns a new secret. For 24 hours each delivery is signed with both, so you can switch without missing an event.- Answering
410turns the webhook off;413drops that event. Any other status, including a redirect, counts as a failure. - A
job.needs_inputevent isn’t retried past its question’s expiry. job.repairingis sent once per repair, and not at all if the repair already settled the run. A run still unsettled atmaintenance.deadline_atfails withrepair_timed_out.- A webhook made with all four earlier events also receives
job.repairing. To stop it,PATCH /v1/webhooks/{id}with theeventsyou want. - Webhooks need the
jobs:readpermission. Only a webhook’s creator changes, tests or rotates it. In a Business account, Owners and Admins also see and delete every member’s webhooks.