Events & webhooks
Receive signed events and recover when delivery is interrupted.
Durable events
Events are recorded in the same database transaction as supported profile, rental and chat changes. A webhook carries IDs and event type, so your bot can fetch fresh authorized context without exposing credentials in delivery payloads.
Verify signatures
Verify the Standard Webhooks signature over the exact raw request body, ID and timestamp. Use webhook-id, webhook-timestamp and webhook-signature. Reject stale timestamps and process each ID once.
Delivery and retries
Delivery is at least once. Return 2xx only after durably inserting the event with a unique event-ID constraint; process it asynchronously. Temporary failures retry with backoff; exhausted deliveries appear in Organization settings → Developers → Webhooks for inspection and replay. A replay keeps the event ID, so it must not create a second bot reply.
Recover missed events
The event feed retains 90 days. An expired cursor returns 410 with a restart boundary; reconcile current resources before restarting there. Download the signature verifier and durable Node receiver example. The receiver queues review tasks and ignores its own messages. Only public HTTPS destinations on port 443 are accepted. Redirects and private network targets are rejected.