Webhooks overview #
HeySora can call your backend when something happens in a conversation, for example a message from an operator or a change of handoff state. These callbacks are webhooks.
Properties #
- Signed. Every delivery carries a signature and a timestamp. Verify them before trusting the payload and reject stale timestamps.
- HTTPS only. Callback URLs must be public HTTPS addresses; redirects are not followed.
- At least once. A delivery is retried with back-off until your endpoint answers with a success status, so handlers must be idempotent. Use the event id to de-duplicate.
- No customer secrets in the URL. Put nothing sensitive in the callback URL.
- Observable. Each organisation can see its delivery log and send a test event from the workspace.
Event types, the envelope, signature verification samples and retry rules are documented in the workspace: Callback webhooks (sign-in required).
Related: authentication, API quick start.