Skip to main content

Webhooks

Ryno sends an HTTP POST to your endpoint when something happens to one of your business customers, including compliance decisions. Every delivery is signed.

Registering your URL and rotating the signing secret are done by a signed-in person in the Partner Portal, not through the API. Your integration implements the receiving side.

Receiving checklist​

  • Verify Ryno-Signature on every request, and reject a timestamp more than five minutes old.
  • Deduplicate on Ryno-Event-Id, which equals the body id and is the same on every retry and replay.
  • Store the event and return any 2xx within 10 seconds, then process it.
  • Ignore an event type you do not recognise.

The signing secret​

The secret is shown once, when the webhook is registered and when the secret is rotated. Store it in your secret manager straight away. It can never be read back. If you lose it, rotate it and use the new value.