Inbound Apple Messages for Business webhook
Receives inbound AMB messages (text, list-picker, form reply, time-picker, Apple Pay events) from Apple. Uses the Authorization: Bearer <jwt> header for HMAC verification per RFC 7515; the router performs a bounded cross-tenant candidate sweep over amb_business_registry and picks the tenant whose secret validates the JWS signing-input. Verified messages are persisted into the tenant inbox before this endpoint acknowledges with { accepted: true }. Persistence failures are logged but acknowledged (Apple retries aggressively on 4xx/5xx).
Authorizations
Dashboard JWT token from Clerk
Headers
Legacy raw JWT (no Bearer prefix).
Apple message id header used as the persistence idempotency key when the body carries none.
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
1 - 255Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.
true, false Body
Apple MSP webhook carrying one inbound message/event; authoring schema consumed by rawBody is a JSON string per the AMB MSP convention.
Apple MSP webhook carrying one inbound message/event; authoring schema consumed by rawBody is a JSON string per the AMB MSP convention.
Response
Acknowledgement envelope. accepted lets Apple stop retrying; persisted / message_id denote whether the inbound message landed in the tenant inbox (false when only a typing indicator was received or persistence failed).
Acknowledgement envelope. accepted lets Apple stop retrying; persisted / message_id denote whether the inbound message landed in the tenant inbox (false when only a typing indicator was received or persistence failed).