Webhook Configuration

@if ($operations === null)
Select an application to configure its webhook.
@else

{{ $operations->application->name }} · Webhook

Manage the tenant delivery webhook used to receive terminal SMS delivery status updates.

Application details
@if ($revealedSecret !== null)

Webhook signing secret

Copy this secret now. It will not be shown again.

{{ $revealedSecret }}

Store the secret in an approved secret manager. Do not place it in URLs, logs, source control, or browser storage.

@endif

Overview

Application
{{ $operations->application->name }}
Application public ID
{{ $operations->application->publicId }}
Environment
{{ config('developer_center.environment') }}
Webhook URL
{{ $operations->webhook?->endpoint ?? 'Not configured' }}
Configuration status
{{ $operations->webhook?->status ?? 'Not configured' }}
Operational status
{{ $operations->webhookStatus->status }}
Signing
{{ $operations->webhook?->signingEnabled ? 'Enabled' : 'Unavailable' }}
Secret
{{ $operations->webhook?->secretState ?? 'Not configured' }}
Created
{{ $operations->webhook?->createdAt ?? 'Not available' }}
Last updated
{{ $operations->webhook?->updatedAt ?? 'Not available' }}

The gateway sends a signed webhook when a correlated delivery receipt reaches delivered, failed, expired, or rejected. Each event has at most one delivery attempt; automatic retries are not implemented.

Readiness

@foreach ($operations->readiness->items as $item)
{{ $item->label }}
{{ $item->state }}@if ($item->evidence !== null) · {{ $item->evidence }}@endif
@endforeach

Configuration

@error('webhook') @enderror @error('endpoint') @enderror @if ($operations->webhook === null)

No webhook is configured for this tenant.

@if ($operations->canManageWebhook)
@csrf
@endif @else @if ($operations->canManageWebhook)
@csrf @method('PUT')
webhook->enabled) data-confirm="Disable webhook delivery? The configuration and delivery history will be preserved." @endif> @csrf @method('PATCH')
@endif @endif
@if ($operations->webhook !== null)

Signing secret

The stored secret is encrypted and cannot be redisplayed. Rotation reveals the replacement once.

@if ($operations->canManageWebhook)
@csrf
@if ($operations->webhook->signingEnabled)
@csrf
@endif @endif
@endif

Signature verification

Read the raw request body. Compute HMAC-SHA256 over X-Webhook-Timestamp + "." + raw_body, prefix the hexadecimal digest with v1=, and compare it with X-Webhook-Signature using a constant-time comparison. Reject timestamps outside the approved five-minute window to limit replay.

$expected = 'v1=' . hash_hmac(
    'sha256',
    $timestamp . '.' . $rawBody,
    $webhookSecret,
);

if (! hash_equals($expected, $signature)) {
    http_response_code(401);
    exit;
}

Delivery status

Last attempt
{{ $operations->webhookStatus->lastAttempt ?? 'Never' }}
Last success
{{ $operations->webhookStatus->lastSuccess ?? 'Never' }}
Last failure
{{ $operations->webhookStatus->lastFailure ?? 'Never' }}
Last HTTP status
{{ $operations->webhookStatus->lastHttpStatus ?? 'Unavailable' }}
Consecutive failures
{{ $operations->webhookStatus->consecutiveFailures ?? 'Unavailable' }}
Test delivery unavailable

The current webhook domain does not implement test-event delivery.

Documentation

@endif