Skip to main content
Set the address in Settings > API > Webhook. Use Send test to see an event arrive before you build on it.

Events

Every event has the same body: the agreement as GET /agreement/{agreementId} returns it, plus id, event and timestamp. Signer events add signer. agreement_signed adds signatureId, round and the invoices it created. Your metadata is in all of them, so you can find your own record (a booking, a Monday item) without a lookup.

Check the signature

Every post carries:
  • X-VisaFlo-Signature: t=<unix seconds>,v1=<hex>
  • X-VisaFlo-Event and X-VisaFlo-Delivery
v1 is the HMAC-SHA256, with your signing secret (shown in Settings > API, starts with whsec_), of the string <t>.<raw body>. Compute it over the raw body, compare in constant time, and reject a t that is more than five minutes old.

Delivery

  • Answer with any 2xx within 10 seconds. Anything else is a failure.
  • A failed post is tried again after 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours and 24 hours (seven tries in all). After that it is marked failed; Settings > API lists the latest deliveries and can send one again.
  • An event can arrive more than once. Use X-VisaFlo-Delivery, or the agreement’s status, to ignore repeats.
  • Addresses must be https:// and public. Redirects are not followed.
  • New secret replaces the signing secret at once. Update your receiver first, or accept both for a while.