Skip to main content
Heyrafiki POSTs a JSON event to your endpoint when something happens. Respond 200 within 10 seconds.

Events

Verifying signatures

Every request carries X-Heyrafiki-Signature, an HMAC-SHA256 of the raw body keyed with your webhook secret.
Compute the HMAC over the raw request body, before any JSON parsing. Re-serialised JSON produces a different signature. Always compare in constant time.
Reject anything that fails verification. Do not fall back to trusting the payload.

Retries

A non-200, a timeout or a connection failure is retried with exponential backoff for 24 hours. Delivery is at-least-once, so handlers must be idempotent: key on event.id and ignore ones you have already processed. Order is not guaranteed. Use created_at to resolve sequence.

Handling

Acknowledge first, work after. Return 200 as soon as you have persisted the event, then process it in a queue. Work done before the response counts against the 10-second timeout.
Last modified on July 25, 2026