Skip to main content
POST
Trigger webhook
This is the URL returned as webhook_url when you create a webhook. It does not use an API key. Instead, every request must carry an HMAC-SHA256 signature of the raw request body, computed with the webhook’s secret_key:
Requests with a missing, malformed, or invalid signature are rejected with 401. Sign the exact bytes you send. If you serialize the JSON once to sign it and again to send it, whitespace or key-order differences will make the signature fail.

GitHub webhooks

GitHub signs deliveries with X-Hub-Signature-256, which uses the same sha256=<hex_digest> format. The endpoint accepts it as an alias, so you can point a GitHub webhook straight at webhook_url:
  1. In your repository, go to Settings > Webhooks > Add webhook.
  2. Set Payload URL to the webhook_url.
  3. Set Content type to application/json.
  4. Set Secret to the webhook’s secret_key.

What happens next

The endpoint returns 202 as soon as the request is accepted. The agent runs in the background with the JSON body as its message. Use the session_id from the response to find the run in Get Webhook Execution Logs or List Recent Webhook Executions.

Headers

X-Webhook-Signature
string

sha256= followed by the hex HMAC-SHA256 of the raw request body, keyed with the webhook's secret_key. Required unless you send X-Hub-Signature-256.

Example:

"sha256=5d41402abc4b2a76b9719d911017c592ae2f7c1d7c3c6f0d8e2b1a4f3c9e8d7b"

X-Hub-Signature-256
string

GitHub-style alias for X-Webhook-Signature. Same format and same signature.

Path Parameters

webhook_id
string
required

ID of the webhook.

Example:

"66f1c3b7e4b0a1b2c3d4e5f7"

Body

application/json

Any JSON payload. It is forwarded to the agent as the message.

The body is of type object.

Response

The trigger was accepted and the agent is running in the background.

message
string
required

Confirmation message.

webhook_id
string
required
Example:

"66f1c3b7e4b0a1b2c3d4e5f7"

agent_id
string
required
Example:

"66e9b0f2a1c3d4e5f6a7b8c9"

session_id
string
required

Agent session ID for this run. Use it to look up the result in the webhook's execution logs.