Heyrafiki POSTs a JSON event to your endpoint when something happens. Respond 200 within 10 seconds.
Events
Verifying signatures
Every request carries X-Heyrafiki-Signature, an HMAC-SHA256 of the raw body keyed with your webhook secret.
Compute the HMAC over the raw request body, before any JSON parsing. Re-serialised JSON produces a different signature. Always compare in constant time.
Reject anything that fails verification. Do not fall back to trusting the payload.
Retries
A non-200, a timeout or a connection failure is retried with exponential backoff for 24 hours. Delivery is at-least-once, so handlers must be idempotent: key on event.id and ignore ones you have already processed.
Order is not guaranteed. Use created_at to resolve sequence.
Handling
Acknowledge first, work after. Return 200 as soon as you have persisted the event, then process it in a queue. Work done before the response counts against the 10-second timeout.