Skip to the content

DEVELOPERS · WEBHOOKS

Webhooks

Seven document events, signed with the Standard Webhooks headers. Verify the raw body, then fetch the document.

webhook-id · webhook-timestamp · webhook-signature

A receiver

Four steps.

ReadRaw body, as bytes
VerifyThree headers
Dedupewebhook-id
Answer 200Queue the work

A DELIVERY CAN ARRIVE MORE THAN ONCE AND OUT OF ORDER. FETCH THE DOCUMENT; DO NOT TRUST THE EVENT AS THE LAST WORD.

FIG. 01 · A RECEIVER, STEP BY STEP

Verify

Refuse a changed body, a wrong secret, an old timestamp.

import { verifyWebhook } from "@docustay/sdk";
const event = await verifyWebhook(process.env.DOCUSTAY_WEBHOOK_SECRET, req.headers, rawBody);

Timestamps more than five minutes old are refused. Any Standard Webhooks library works with the secret (whsec_…).

Delivery you can debug.

01

Retries

A failed delivery is retried, and every attempt is in the delivery log.

02

Replay

Send again replays an event as often as you like, so you can fix the receiver without making another document.

03

Rotation

Rotate an endpoint's secret without recreating the endpoint.

Questions

Quick answers.

Can I send to localhost?

No. Endpoints must be public https addresses. Use a tunnel, or npx docustay listen --forward-to.

Does an event carry a signing link?

Never. Events carry facts about the document, not links or codes.

Which event means finished?

documents.document.executed: everyone signed and the sealed copy exists.

Add an endpoint.

Create an API key