Integration
Events run.failed / run.recovered, X-Pathly-*-Header und Signaturprüfung.
OpenAPI-VertragAPI-Schlüssel ausstellenKostenloses Solo-Konto
API-Schlüssel holen (kostenlose Anmeldung)
Vollständiges Dokument, ohne Authentifizierung, bereit für Ihren Client-Generator.
Events: run.failed, run.recovered. Header X-Pathly-* mit HMAC-SHA256. URL bleibt verschlüsselt; Lesen liefert eine Prüfsumme.
Signatur in konstanter Zeit prüfen. Alte Zeitstempel ablehnen. Schnell 2xx antworten, danach asynchron verarbeiten.
Créer
curl -X POST https://api.pathlyhq.com/v1/webhooks \
-H "Authorization: Bearer $PATHLY_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"url": "https://www.example.com/hooks/pathly",
"events": ["run.failed", "run.recovered"]
}'Node — vérifier la signature
import { createHmac, timingSafeEqual } from "node:crypto";
function verify(secret, timestamp, rawBody, signature) {
const expected =
"sha256=" +
createHmac("sha256", secret)
.update(`${timestamp}.${rawBody}`)
.digest("hex");
const a = Buffer.from(signature);
const b = Buffer.from(expected);
return a.length === b.length && timingSafeEqual(a, b);
}Python — vérifier la signature
import hashlib, hmac
def verify(secret: str, timestamp: str, raw_body: bytes, signature: str) -> bool:
digest = hmac.new(
secret.encode(), f"{timestamp}.".encode() + raw_body, hashlib.sha256
).hexdigest()
expected = f"sha256={digest}"
return hmac.compare_digest(expected, signature)