Webhooks
Ryno sends an HTTP POST to your endpoint when something happens to one of your business customers, including compliance decisions. Every delivery is signed.
Registering your URL and rotating the signing secret are done by a signed-in person in the Partner Portal, not through the API. Your integration implements the receiving side.
Verifying deliveries
Headers, the Ryno-Signature scheme, the body and acknowledging.
Events and payloads
Every event and the data it carries.
Retries and endpoint health
The retry schedule and when an endpoint is disabled.
Managing your webhook
Register a URL, rotate the secret, replay deliveries.
Receiving checklist
- Verify
Ryno-Signatureon every request, and reject a timestamp more than five minutes old. - Deduplicate on
Ryno-Event-Id, which equals the bodyidand is the same on every retry and replay. - Store the event and return any
2xxwithin 10 seconds, then process it. - Ignore an event
typeyou do not recognise.
The signing secret
The secret is shown once, when the webhook is registered and when the secret is rotated. Store it in your secret manager straight away. It can never be read back. If you lose it, rotate it and use the new value.