FlowManner
Chat
Sign InGet Started
Flowmanner
Menu
  • Chat
  • Agents
  • Pricing
  • Docs
  • About
Products
  • Workflows
  • Templates
  • Changelog
  • Missions
Resources
  • Blog
  • API Reference
More
  • Careers
  • Contact
  • Security
  • Start
    • Quickstart
    • Your First Mission
    • Your First Eval
  • How-to
    • Connect Your Own Keys (BYOK)
    • Switch Models Per Task
    • Publish a Template
    • Run Evaluations
    • Chat with Artifacts & Previews
    • Automate via the API
    • Webhooks & Triggers
  • Concepts
    • Glossary
    • Execution Model
    • Models & Routing
    • Sandboxes & Previews
    • Memory & Privacy
    • Trust Model
  • Reference
    • Reference · API
      • Authentication
      • Missions & Runs
      • Chat & Sandboxes
      • Blueprints, Graphs & Templates
      • Evaluations & Feedback
      • Marketplace & Community
      • Files & Exports
      • Integrations & Webhooks
      • Agents & Orchestration
      • Auth, Workspaces & Billing
      • Memory & Knowledge
      • Notifications
      • Platform Services
    • Errors
    • Models
    • Limits

Webhooks & Triggers

Receive Flowmanner webhook events and verify their HMAC signatures.

  1. Expose an HTTPS endpoint that can accept POSTs.
  2. Point a trigger at it: ingest URL is POST /api/triggers/webhook/{webhook_path} — the {webhook_path} tail is your trigger's unique path segment (triggers.py:189).
  3. Verify every delivery. Requests carry X-Signature: HMAC-SHA256 over the raw request body (hex or sha256= prefixed; X-Hub-Signature-256 accepted). Verify with your signing secret before trusting a payload — implementation: trigger_service.verify_webhook_signature.
  4. Respond fast, then process async; non-2xx answers make deliveries retryable.
  5. Legacy docs showed fictional /api/webhooks/wh_* URLs and an X-Webhook-Secret header — those never existed; this page is the contract.

Last updated 2026-08-25 (git-derived)