{
"id": "<string>",
"api_version": "v1",
"occurred_at": "2023-11-07T05:31:56Z",
"partner_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"org_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"org_external_ref": "<string>",
"brand_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"brand_name": "<string>",
"brand_external_ref": "<string>",
"country": null,
"type": "webhook.test",
"data": {
"endpoint_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"message": "<string>"
}
}webhook.test
The verification ping, sent only when you call the test route on one of your endpoints.
{
"id": "<string>",
"api_version": "v1",
"occurred_at": "2023-11-07T05:31:56Z",
"partner_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"org_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"org_external_ref": "<string>",
"brand_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"brand_name": "<string>",
"brand_external_ref": "<string>",
"country": null,
"type": "webhook.test",
"data": {
"endpoint_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"message": "<string>"
}
}POST /webhook-endpoints/{endpointId}/test, and your 2xx makes a pending_verification or failing endpoint active. See Webhook events for the envelope.Authorizations
A Surfais API key — an organisation key or a partner key. Issued by Surfais; shown once. Rotate by creating a new key, then revoking the old one.
Headers
The envelope's id — dedupe on it; retries repeat it.
Unix seconds when THIS attempt was sent; reject if further than the documented tolerance from your clock.
v1= + hex(HMAC-SHA256(secret, ".")).
Body
evt_ + ULID. Retries carry the same id — dedupe on it.
"v1"RFC 3339 timestamp.
UUID.
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$UUID.
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Your external_ref on the partner–org link.
UUID.
^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$Your external_ref on the brand.
Reserved: per-market events are a v1.1 deferral; always null in v1.
"webhook.test"Show child attributes
Show child attributes
Response
Accepted. Any 2xx counts; the body is ignored (its first bytes are kept for your delivery log).