Event types
Events are named resource.action, so one endpoint can follow a whole area of the platform. The most used ones are deploy.succeeded, deploy.failed, service.scaled, and incident.opened. Each payload includes the workspace, the service, and a link back to the dashboard.
Verifying signatures
Every request includes a Webhook-Signature header: a timestamp and an HMAC of the raw body, made with the endpoint secret. Compare it with your own HMAC and reject requests older than five minutes to block replays.
Retries and ordering
A delivery succeeds when your endpoint answers with a 2xx status within ten seconds. Anything else is retried with backoff for 24 hours. Events can arrive out of order, so use the created_at field and the event id rather than arrival time.