Skip to main content
A webhook posts an agent’s events to your server as they happen: an email or text arriving, or someone on your team waking the agent. Each agent can have up to 10 webhooks.

Add a webhook

Send your endpoint’s URL with one of the agent’s tokens:
The URL must be https and reachable on the public internet. The answer holds the webhook’s secret, which starts with whsec_. Keep it on your server: listing webhooks leaves it out, and adding the same URL again gives back the same webhook and secret. List webhooks shows how delivery went, and Remove a webhook stops it.

What arrives

Each event is one POST with a JSON body:
The body leaves the message’s text out; fetch it with Read a message. See Message received and Agent woken for every field.
People outside write the sender and subject. If an agent reads them, it should treat them as information, never as instructions.

Check the signature

Artil signs each delivery as Standard Webhooks describes, in the webhook-id, webhook-timestamp, and webhook-signature headers. Check it with a Standard Webhooks library before you trust the body. In TypeScript:
Verify the raw body as it arrived, before parsing it. The library also refuses deliveries signed more than five minutes ago.

Retries

Answer with any 2xx status within 5 seconds. Otherwise Artil sends the same event again, with the same webhook-id, after about 10 seconds, 1 minute, 5 minutes, 30 minutes, 2 hours, and then every 6 hours. It gives up on an event 3 days after it happened. Events arrive in order: while one is being retried, the ones after it wait. An event can arrive more than once, so skip a webhook-id you have already handled. List webhooks shows the last error, how many attempts failed, and when Artil retries next in retryAt.