Intégration

Webhooks sortants signés HMAC

Événements run.failed / run.recovered, en-têtes X-Pathly-* et vérification de signature.

Contrat OpenAPIÉmettre une clé d’APICompte Solo gratuit

Document complet, sans authentification, à donner à votre générateur de client.

Webhooks sortants

Événements supportés : run.failed, run.recovered. En-têtes : X-Pathly-Id, X-Pathly-Event, X-Pathly-Timestamp, X-Pathly-Signature (HMAC-SHA256 de `${timestamp}.${rawBody}`, préfixe sha256=). L’URL reste chiffrée au repos ; la lecture expose une empreinte.

Vérifiez la signature en temps constant (timingSafeEqual). Rejetez les horodatages trop anciens (replay). Répondez 2xx rapidement ; traitez ensuite en file.

Créer

curl -X POST https://api.pathlyhq.com/v1/webhooks \
  -H "Authorization: Bearer $PATHLY_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://www.example.com/hooks/pathly",
    "events": ["run.failed", "run.recovered"]
  }'

Node — vérifier la signature

import { createHmac, timingSafeEqual } from "node:crypto";

function verify(secret, timestamp, rawBody, signature) {
  const expected =
    "sha256=" +
    createHmac("sha256", secret)
      .update(`${timestamp}.${rawBody}`)
      .digest("hex");
  const a = Buffer.from(signature);
  const b = Buffer.from(expected);
  return a.length === b.length && timingSafeEqual(a, b);
}

Python — vérifier la signature

import hashlib, hmac

def verify(secret: str, timestamp: str, raw_body: bytes, signature: str) -> bool:
    digest = hmac.new(
        secret.encode(), f"{timestamp}.".encode() + raw_body, hashlib.sha256
    ).hexdigest()
    expected = f"sha256={digest}"
    return hmac.compare_digest(expected, signature)