txt-fil.es / developers / webhooks

Webhook documentation

Create and list endpoints

Use GET

Verify deliveries

Treat the signing secret as a credential. Verify the request signature against the unchanged request body before parsing or acting, reject stale or invalid deliveries, and make handlers idempotent because transient failures may be retried.

Operate safely

Return a successful status only after durable acceptance, record the txt request and event identifiers, use backoff for downstream work, and revoke any endpoint whose secret may have been exposed. Never place bearer credentials in webhook URLs or note bodies.