sync.
Receiving webhooks
Apush listener receives the provider’s webhook deliveries at a URL your
deployment serves. Its ingress declares how a delivery is authenticated and
identified:
bijection/billing.ts
deliveryis where a delivery names itself, in a header or the body. Repeated deliveries with the same identity are recognized as duplicates.authenticationis the provider’s signature scheme. The signing secret is never in the definition: you provide it as a credential when you configure the listener.bodyandmax_body_bytesbound what a delivery may contain. Larger deliveries are refused before any verification work.proves: "refresh_hint"makes each accepted delivery request a sync.
Where the provider opens and closes notification channels through its API, add
a
subscription naming the HTTP contracts that do it (watch and stop), and
Bijection manages the channel’s lifecycle. Where you register the webhook URL in
the provider’s own console, declare no subscription.
Configuring the listener
Store the provider’s signing secret as a credential. Unlike an HTTP credential, it is the raw secret, not a JSON envelope:--disable.
bijection integration listener-status <source> shows the listener’s health
separately from the source’s syncs: syncs can keep data current while
notifications are failing, and a healthy listener can coexist with a blocked
sync.
Polling for changes
When a provider publishes a feed of change events rather than calling you, declare apull listener instead. It names the HTTP contract to poll, its
polling interval bounds, and how the poll continues from one request to the
next. Each change it observes requests a sync, exactly as a delivery does. A
pull listener takes no --callback-url.
Webhook events for operations
Some webhooks announce business events you want to act on one by one, rather than changes to re-read. Declareproves: "occurrence" to keep each verified
event and hand it to one operation:
- The delivery identity must be in the body, and the body must be
{ kind: "json", validator: v.any() }with amax_body_bytesof at most 61,440. shared_tokenauthentication and asubscriptionaren’t allowed.
ctx.occurrence.payload(), which returns the exact JSON string the provider
sent. webhook-status, webhook-event and webhook-control inspect and manage
the retained events; see the CLI reference.