Skip to main content
WEBHOOK
Fires when an own brand’s AIS Score moves by at least a subscription’s min_delta, in the subscription’s direction, between two consecutive scored dates. See Webhook events for the fields and for how thresholds are judged, including the moves that never fire.

Authorizations

Authorization
string
header
required

A Surfais API key — an organisation key or a partner key. Issued by Surfais; shown once. Rotate by creating a new key, then revoking the old one.

Headers

X-Surfais-Event-Id
string
required

The envelope's id — dedupe on it; retries repeat it.

X-Surfais-Timestamp
string
required

Unix seconds when THIS attempt was sent; reject if further than the documented tolerance from your clock.

X-Surfais-Signature
string
required

v1= + hex(HMAC-SHA256(secret, ".")).

Body

application/json
id
string
required

evt_ + ULID. Retries carry the same id — dedupe on it.

api_version
string
required
Allowed value: "v1"
occurred_at
string<date-time>
required

RFC 3339 timestamp.

partner_id
string<uuid>
required

UUID.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
org_id
string<uuid> | null
required

UUID.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
org_external_ref
string | null
required

Your external_ref on the partner–org link.

brand_id
string<uuid> | null
required

UUID.

Pattern: ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
brand_name
string | null
required
brand_external_ref
string | null
required

Your external_ref on the brand.

country
null
required

Reserved: per-market events are a v1.1 deferral; always null in v1.

type
string
required
Allowed value: "score.threshold_crossed"
data
object
required
threshold
object
required

The subscription rule that matched, frozen at emission so every retry carries the same block.

Response

Accepted. Any 2xx counts; the body is ignored (its first bytes are kept for your delivery log).