Skip to main content
WEBHOOK
Fires once per own brand per scan date, for every own brand the scan measured, after that date’s scores are stored. See Webhook events for every field, and for what a null metric means.

Authorizations

Authorization
string
header
required

A Surfais API key — an organisation key or a partner key. Issued by Surfais; shown once. Rotate by creating a new key, then revoking the old one.

Headers

X-Surfais-Event-Id
string
required

The envelope's id — dedupe on it; retries repeat it.

X-Surfais-Timestamp
string
required

Unix seconds when THIS attempt was sent; reject if further than the documented tolerance from your clock.

X-Surfais-Signature
string
required

v1= + hex(HMAC-SHA256(secret, ".")).

Body

application/json
id
string
required

evt_ + ULID. Retries carry the same id — dedupe on it.

api_version
string
required
Allowed value: "v1"
occurred_at
string<date-time>
required

RFC 3339 timestamp.

partner_id
string<uuid>
required

UUID.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
org_id
string<uuid> | null
required

UUID.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
org_external_ref
string | null
required

Your external_ref on the partner–org link.

brand_id
string<uuid> | null
required

UUID.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
brand_name
string | null
required
brand_external_ref
string | null
required

Your external_ref on the brand.

country
null
required

Reserved: per-market events are a v1.1 deferral; always null in v1.

type
string
required
Allowed value: "scan.completed"
data
object
required

Response

Accepted. Any 2xx counts; the body is ignored (its first bytes are kept for your delivery log).