Events
Every event has the same body: the agreement as
GET /agreement/{agreementId} returns it, plus id, event and timestamp. Signer events add signer. agreement_signed adds signatureId, round and the invoices it created. Your metadata is in all of them, so you can find your own record (a booking, a Monday item) without a lookup.
Check the signature
Every post carries:X-VisaFlo-Signature: t=<unix seconds>,v1=<hex>X-VisaFlo-EventandX-VisaFlo-Delivery
v1 is the HMAC-SHA256, with your signing secret (shown in Settings > API, starts with whsec_), of the string <t>.<raw body>. Compute it over the raw body, compare in constant time, and reject a t that is more than five minutes old.
Delivery
- Answer with any
2xxwithin 10 seconds. Anything else is a failure. - A failed post is tried again after 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours and 24 hours (seven tries in all). After that it is marked failed; Settings > API lists the latest deliveries and can send one again.
- An event can arrive more than once. Use
X-VisaFlo-Delivery, or the agreement’sstatus, to ignore repeats. - Addresses must be
https://and public. Redirects are not followed. - New secret replaces the signing secret at once. Update your receiver first, or accept both for a while.