curl --request POST \
--url https://api.orbit.devotel.io/api/v1/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"url": "https://yourapp.com/webhooks/orbit",
"events": [
"message.delivered",
"message.failed",
"call.completed"
],
"secret": "<string>",
"active": true,
"description": "<string>",
"timeout_seconds": 30,
"headers": {},
"retry_policy": {
"max_retries": 5,
"initial_delay_ms": 43200050
}
}
'import requests
url = "https://api.orbit.devotel.io/api/v1/webhooks"
payload = {
"url": "https://yourapp.com/webhooks/orbit",
"events": ["message.delivered", "message.failed", "call.completed"],
"secret": "<string>",
"active": True,
"description": "<string>",
"timeout_seconds": 30,
"headers": {},
"retry_policy": {
"max_retries": 5,
"initial_delay_ms": 43200050
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
url: 'https://yourapp.com/webhooks/orbit',
events: ['message.delivered', 'message.failed', 'call.completed'],
secret: '<string>',
active: true,
description: '<string>',
timeout_seconds: 30,
headers: {},
retry_policy: {max_retries: 5, initial_delay_ms: 43200050}
})
};
fetch('https://api.orbit.devotel.io/api/v1/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.orbit.devotel.io/api/v1/webhooks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://yourapp.com/webhooks/orbit',
'events' => [
'message.delivered',
'message.failed',
'call.completed'
],
'secret' => '<string>',
'active' => true,
'description' => '<string>',
'timeout_seconds' => 30,
'headers' => [
],
'retry_policy' => [
'max_retries' => 5,
'initial_delay_ms' => 43200050
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.orbit.devotel.io/api/v1/webhooks"
payload := strings.NewReader("{\n \"url\": \"https://yourapp.com/webhooks/orbit\",\n \"events\": [\n \"message.delivered\",\n \"message.failed\",\n \"call.completed\"\n ],\n \"secret\": \"<string>\",\n \"active\": true,\n \"description\": \"<string>\",\n \"timeout_seconds\": 30,\n \"headers\": {},\n \"retry_policy\": {\n \"max_retries\": 5,\n \"initial_delay_ms\": 43200050\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.orbit.devotel.io/api/v1/webhooks")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://yourapp.com/webhooks/orbit\",\n \"events\": [\n \"message.delivered\",\n \"message.failed\",\n \"call.completed\"\n ],\n \"secret\": \"<string>\",\n \"active\": true,\n \"description\": \"<string>\",\n \"timeout_seconds\": 30,\n \"headers\": {},\n \"retry_policy\": {\n \"max_retries\": 5,\n \"initial_delay_ms\": 43200050\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.orbit.devotel.io/api/v1/webhooks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://yourapp.com/webhooks/orbit\",\n \"events\": [\n \"message.delivered\",\n \"message.failed\",\n \"call.completed\"\n ],\n \"secret\": \"<string>\",\n \"active\": true,\n \"description\": \"<string>\",\n \"timeout_seconds\": 30,\n \"headers\": {},\n \"retry_policy\": {\n \"max_retries\": 5,\n \"initial_delay_ms\": 43200050\n }\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": "<string>",
"url": "<string>",
"events": [
"<string>"
],
"active": true,
"description": "<string>",
"timeout_seconds": 15,
"secret": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "<string>",
"status": 429,
"retry_after": 2
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}Register a webhook endpoint
Register a webhook endpoint to receive event notifications. URL must be HTTPS and not target a private/loopback/link-local/CGNAT host (SSRF defense). Optional secret is used to compute the X-Devotel-Signature HMAC; if omitted, Devotel auto-generates one and returns it in the response (this is the only time the secret is returned in cleartext — it is encrypted at rest after).
curl --request POST \
--url https://api.orbit.devotel.io/api/v1/webhooks \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"url": "https://yourapp.com/webhooks/orbit",
"events": [
"message.delivered",
"message.failed",
"call.completed"
],
"secret": "<string>",
"active": true,
"description": "<string>",
"timeout_seconds": 30,
"headers": {},
"retry_policy": {
"max_retries": 5,
"initial_delay_ms": 43200050
}
}
'import requests
url = "https://api.orbit.devotel.io/api/v1/webhooks"
payload = {
"url": "https://yourapp.com/webhooks/orbit",
"events": ["message.delivered", "message.failed", "call.completed"],
"secret": "<string>",
"active": True,
"description": "<string>",
"timeout_seconds": 30,
"headers": {},
"retry_policy": {
"max_retries": 5,
"initial_delay_ms": 43200050
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
url: 'https://yourapp.com/webhooks/orbit',
events: ['message.delivered', 'message.failed', 'call.completed'],
secret: '<string>',
active: true,
description: '<string>',
timeout_seconds: 30,
headers: {},
retry_policy: {max_retries: 5, initial_delay_ms: 43200050}
})
};
fetch('https://api.orbit.devotel.io/api/v1/webhooks', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.orbit.devotel.io/api/v1/webhooks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://yourapp.com/webhooks/orbit',
'events' => [
'message.delivered',
'message.failed',
'call.completed'
],
'secret' => '<string>',
'active' => true,
'description' => '<string>',
'timeout_seconds' => 30,
'headers' => [
],
'retry_policy' => [
'max_retries' => 5,
'initial_delay_ms' => 43200050
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.orbit.devotel.io/api/v1/webhooks"
payload := strings.NewReader("{\n \"url\": \"https://yourapp.com/webhooks/orbit\",\n \"events\": [\n \"message.delivered\",\n \"message.failed\",\n \"call.completed\"\n ],\n \"secret\": \"<string>\",\n \"active\": true,\n \"description\": \"<string>\",\n \"timeout_seconds\": 30,\n \"headers\": {},\n \"retry_policy\": {\n \"max_retries\": 5,\n \"initial_delay_ms\": 43200050\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.orbit.devotel.io/api/v1/webhooks")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://yourapp.com/webhooks/orbit\",\n \"events\": [\n \"message.delivered\",\n \"message.failed\",\n \"call.completed\"\n ],\n \"secret\": \"<string>\",\n \"active\": true,\n \"description\": \"<string>\",\n \"timeout_seconds\": 30,\n \"headers\": {},\n \"retry_policy\": {\n \"max_retries\": 5,\n \"initial_delay_ms\": 43200050\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.orbit.devotel.io/api/v1/webhooks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://yourapp.com/webhooks/orbit\",\n \"events\": [\n \"message.delivered\",\n \"message.failed\",\n \"call.completed\"\n ],\n \"secret\": \"<string>\",\n \"active\": true,\n \"description\": \"<string>\",\n \"timeout_seconds\": 30,\n \"headers\": {},\n \"retry_policy\": {\n \"max_retries\": 5,\n \"initial_delay_ms\": 43200050\n }\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": "<string>",
"url": "<string>",
"events": [
"<string>"
],
"active": true,
"description": "<string>",
"timeout_seconds": 15,
"secret": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "<string>",
"status": 429,
"retry_after": 2
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}Authorizations
Dashboard JWT token from Clerk
Headers
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
1 - 255Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.
true, false Body
HTTPS endpoint URL.
"https://yourapp.com/webhooks/orbit"
Subscribed event types (e.g. message.delivered, call.completed, verification.approved). Pass ["*"] to subscribe to every event type, including ones added later.
1[
"message.delivered",
"message.failed",
"call.completed"
]
Optional shared secret. Used to verify the X-Devotel-Signature HMAC on every delivery.
16Whether to start dispatching events immediately.
255Per-endpoint HTTP delivery timeout in seconds (1-30). The dispatcher aborts an in-flight delivery once this many seconds elapse. Defaults to 30 (the platform hard ceiling) when omitted.
1 <= x <= 30Optional per-endpoint custom request headers (e.g. {"Authorization": "Bearer …", "X-API-Key": "…"}) sent on every delivery so you can authenticate to gateways/middleware that require header-based auth. Up to 20 headers. Orbit-managed headers (Content-Type, the X-Devotel-/X-Orbit- signature + identity headers, Idempotency-Key, User-Agent) cannot be overridden and are rejected.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes