POST /api/webhook-endpoints returns secret once (gwhsec_…). List and later reads never include it.
DELETE /api/webhook-endpoints/{endpointId} removes it. GET /api/webhook-endpoints lists id, url, events, isActive, and createdAt.
Events
Envelope
agent.started uses status: "QUEUED". agent.failed uses FAILED or CANCELLED, and a thrown turn adds error. tool.completed data includes toolName, output, assets, creditCost, and durationMs.
Signature
string
sha256=<hex>.string
Unix seconds used in the HMAC.
string
Event name.
string
Delivery row id.
sha256= with a constant-time check.
Each endpoint, event, and run (or tool call) is delivered once. A duplicate emit is not posted again. A timeout or non-2xx response is retried up to 4 times, waiting 1s, then 5s, then 15s. Each attempt is signed with a fresh timestamp. The row stays
PENDING until the last failure, then FAILED. A failed delivery does not fail the agent turn.