Webhooks
Receive extraction results via HTTPS POST when async jobs complete.
Setup
- Save
webhook_secretfrom registration (or rotate it anytime from the dashboard) - Pass
webhook_urlwithoptions[async]=true - Verify
X-Extract-Signatureon every incoming request
Delivery
We POST the full extraction JSON (same schema as sync 200 response) to your URL.
POST https://your-app.com/webhooks/extract
Content-Type: application/json
X-Extract-Signature: sha256=a1b2c3...
X-Extract-Event: extraction.completed
X-Extract-Request-Id: 550e8400-e29b-41d4-a716-446655440000
Signature verification
Compute HMAC-SHA256 of the raw request body using your webhook_secret:
// PHP example
$expected = 'sha256=' . hash_hmac('sha256', $rawBody, $webhookSecret);
if (!hash_equals($expected, $_SERVER['HTTP_X_EXTRACT_SIGNATURE'])) {
http_response_code(401);
exit;
}
Retry policy
Failed deliveries (non-2xx or timeout) are retried with exponential backoff:
- Max attempts: 3
- Backoff: 30, 120, 300 seconds
- Timeout per attempt: 30 s
Events
| X-Extract-Event | Description |
|---|---|
extraction.completed | Successful extraction |
extraction.failed | Pipeline error |
Stripe webhooks (billing)
Payment webhooks are separate — Stripe sends events to
POST https://cyber.lerepop.lv/api/v1/webhooks/stripe.
Configure in Stripe Dashboard or via stripe listen --forward-to ... locally.