Reference
Webhooks
Signed, retried, and safe to point anywhere.
Events are delivered to your endpoint with an HMAC signature over the raw body. Verify before you parse, a body you have parsed is a body you have already trusted.
http
Events
| Event | Fires when |
|---|---|
usage.recorded | A call settled and wrote a usage row |
wallet.low | An end user's available balance crossed your threshold |
wallet.exhausted | A call was refused for insufficient credit |
key.revoked | A key stopped working |
invoice.paid | A charge succeeded |
Delivery
Retried with exponential backoff for 24 hours. Deliveries are at-least-once, so handlers must be idempotent, the event id is stable across retries.
Outbound requests are SSRF-protected: private ranges and link-local addresses are refused, so a webhook URL cannot be used to reach inside our network.