For AI agents: the complete documentation index is available at /llms.txt, the full documentation bundle is available at /llms-full.txt, and this page is available as Markdown at /devbase/v1/webhooks.md.

Webhooks

Availability: The DevBase runtime and production API are not yet deployed. This page describes the committed v1 contract for integration planning; requests to the API URL will not succeed until the runtime is released.

Terminal Job events are delivered at least once with metadata-only payloads. Fetch results and detailed errors through the authenticated API. The exact raw body is signed in DevBase-Signature: t=<unix>,v1=<hmac-sha256>; verify the timestamp within your replay window, then compute HMAC-SHA256 over the ASCII bytes of <timestamp>.<exact raw body> using the UTF-8 bytes of the returned signing-secret string as the HMAC key. Encode the digest as lowercase hexadecimal and compare the supplied v1 value in constant time. During the 24-hour rotation window, the header contains both signatures as repeated parameters, for example DevBase-Signature: t=<unix>,v1=<old-hmac-sha256>,v1=<new-hmac-sha256>; accepting either valid signature is sufficient.

The signed body is an immutable versioned JSON envelope. id is the UUID v7 event ID and the stable deduplication key; type is job.terminal; and version is the integer payload version.

{
  "id": "01900000-0000-7000-8000-000000000001",
  "type": "job.terminal",
  "version": 1,
  "createdAt": "2026-01-01T00:00:00Z",
  "workspaceId": "01900000-0000-7000-8000-000000000002",
  "jobId": "01900000-0000-7000-8000-000000000003",
  "state": "JOB_STATE_SUCCEEDED",
  "resourceVersion": "7"
}

The payload is metadata-only: it contains no result or terminal-error body. Use workspaceId and jobId with the authenticated API to fetch current Job metadata. Redelivery preserves the exact body and therefore the same id.

Endpoints must be public HTTPS URLs. DevBase rejects loopback, private, link-local, metadata-service, non-HTTP, and redirect targets and revalidates DNS before delivery.

Rotation signs with both old and new secrets for 24 hours. Delivery starts immediately and retries up to eight total attempts over 24 hours with jittered exponential backoff. A delivery attempt times out after 10 seconds; timeouts, 429, and 5xx retry; other 4xx responses stop automatic retries. Manual redelivery uses the current valid secret set. Deleting an endpoint stops pending retries.