Ex Extract API

Webhooks

Receive extraction results via HTTPS POST when async jobs complete.

Setup

  1. Save webhook_secret from registration (or rotate it anytime from the dashboard)
  2. Pass webhook_url with options[async]=true
  3. Verify X-Extract-Signature on every incoming request

Delivery

We POST the full extraction JSON (same schema as sync 200 response) to your URL.

POST https://your-app.com/webhooks/extract
Content-Type: application/json
X-Extract-Signature: sha256=a1b2c3...
X-Extract-Event: extraction.completed
X-Extract-Request-Id: 550e8400-e29b-41d4-a716-446655440000

Signature verification

Compute HMAC-SHA256 of the raw request body using your webhook_secret:

// PHP example
$expected = 'sha256=' . hash_hmac('sha256', $rawBody, $webhookSecret);
if (!hash_equals($expected, $_SERVER['HTTP_X_EXTRACT_SIGNATURE'])) {
    http_response_code(401);
    exit;
}

Retry policy

Failed deliveries (non-2xx or timeout) are retried with exponential backoff:

  • Max attempts: 3
  • Backoff: 30, 120, 300 seconds
  • Timeout per attempt: 30 s

Events

X-Extract-EventDescription
extraction.completedSuccessful extraction
extraction.failedPipeline error

Stripe webhooks (billing)

Payment webhooks are separate — Stripe sends events to POST https://cyber.lerepop.lv/api/v1/webhooks/stripe. Configure in Stripe Dashboard or via stripe listen --forward-to ... locally.