Skip to Content
WebhooksOverview

Webhooks

Webhooks push events to your systems as they happen: an alert opens, a weekly sampling completes, a fix is verified, an order is attributed to an AI assistant… Instead of polling the API, you expose an HTTPS endpoint and Skoup calls it.

Typical uses: open a ticket in your tracker when a critical alert opens, post the weekly sampling results to a data warehouse, trigger an n8n or Zapier workflow, refresh a client dashboard.

Set up an endpoint

Expose an HTTPS URL

Your endpoint must accept POST requests with a JSON body, over HTTPS, on a publicly reachable host. Addresses resolving to private, loopback or link-local IPs are refused. To test from your machine, use a tunnel (ngrok, Cloudflare Tunnel…) — see Best practices.

Register it

In Settings → Developers → Webhooks, click Add endpoint, paste the URL, pick the event types to receive (or all of them) and, optionally, restrict it to some brands.

Or from the API, with a key holding the webhooks:write scope:

curl https://api.skoup.ai/v1/webhook_endpoints \ -H "Authorization: Bearer skoup_test_4eC39HqLyjWDarjtT1zdp7dc" \ -H "Content-Type: application/json" \ -d '{ "url": "https://hooks.example.com/skoup", "enabled_events": ["alert.created", "alert.resolved", "sampling.completed"], "description": "Alerts to our ticketing" }'

The response contains the endpoint’s signing secret (whsec_…). The API returns it only in this response; it stays available in the dashboard behind a Reveal button.

Verify the signature

Every delivery is signed with the endpoint’s secret. Always verify it before trusting a payload — see Verifying signatures.

Answer 2xx quickly

Return any 2xx status within 10 seconds. Anything else — or a timeout — counts as a failure and is retried.

The event object

Every delivery is a POST whose body is an event:

{ "id": "evt_8KpL3mQn6RsT9uVw2xYz4A", "object": "event", "type": "alert.created", "api_version": "v1", "created": "2026-09-21T02:47:12Z", "livemode": true, "brand": "br_2xKq8Fh3LmN9pQrT4vWy6Z", "data": { "object": { "id": "alrt_5TgH2kLm8NpQ3rSv6wXy9A", "object": "alert", "kind": "price_hallucination", "severity": "critical", "status": "new", "…": "…" } } }
FieldDescription
idUnique ID of the event. The same event delivered twice keeps the same ID.
typeWhat happened, as resource.action. See Event types.
api_versionVersion of the payload format. Always v1 today.
createdWhen the event happened (UTC).
livemodefalse for events produced in test mode.
brandThe brand concerned.
data.objectThe object concerned, in the exact shape returned by the matching GET endpoint.
data.previous_attributesOn *.updated events, the previous values of the fields that changed.

HTTP headers

HeaderValue
Content-Typeapplication/json
User-AgentSkoup-Webhooks/1.0
X-Skoup-Signaturet=…,v1=… — see Verifying signatures
X-Skoup-Event-IdThe event ID (evt_…), to deduplicate.
X-Skoup-Event-TypeThe event type, to route without parsing the body.
X-Skoup-Delivery-IdThe ID of this delivery attempt (whd_…).

Catching up with the Events API

Events are also available through the API for 30 days, which lets you catch up after an outage or reconcile periodically:

curl "https://api.skoup.ai/v1/events?type=alert.created&limit=100" \ -H "Authorization: Bearer skoup_test_4eC39HqLyjWDarjtT1zdp7dc"

Webhooks tell you that something happened; the event carries a snapshot of the object at that moment. If you need the latest state, fetch the object with its ID.

Last updated on