Receive an inbound vendor webhook

Accept a vendor callback addressed by its opaque URL token. This endpoint is NOT authenticated via bearer token; the URL token is the only credential. Rate-limited per token to protect against vendor retry storms.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
string
required
length between 1 and 256

Opaque inbound-webhook token issued at RequirementDefinition create time and embedded in the URL given to the vendor.

Body Params

Opaque vendor payload, signature-verified and validated against the vendor contract server-side.

Headers
string
required

HMAC signature over the signing string X-Wingspan-Timestamp + "." + rawRequestBody, keyed by the vendor secret bound to the URL token. Required second factor — the URL token alone (which travels in the path and may appear in logs/proxies) is not sufficient.

string
required

Unix-seconds timestamp covered by the signature. Requests whose timestamp is outside a ±300s skew window are rejected as replays.

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json