Reference

Webhooks

Signed, retried, and safe to point anywhere.

Events are delivered to your endpoint with an HMAC signature over the raw body. Verify before you parse, a body you have parsed is a body you have already trusted.

http

Events

EventFires when
usage.recordedA call settled and wrote a usage row
wallet.lowAn end user's available balance crossed your threshold
wallet.exhaustedA call was refused for insufficient credit
key.revokedA key stopped working
invoice.paidA charge succeeded

Delivery

Retried with exponential backoff for 24 hours. Deliveries are at-least-once, so handlers must be idempotent, the event id is stable across retries.

Outbound requests are SSRF-protected: private ranges and link-local addresses are refused, so a webhook URL cannot be used to reach inside our network.