Register an app
Create a webhook app and copy the HMAC secret once.
A webhook app is the inbound partner identity. The appId in the ingest URL must match this registry.
Steps
- Open Portal Webhooks → Apps.
- Register an app with a stable id (for example
acme). That id is{appId}in the URL. - Copy the HMAC secret. It is shown once.
- Give the id, URL, and secret to the partner. They never get a Portal login.
Secret shown once
After you leave the flash banner, Connect will not display the plaintext again. Rotate by registering a new app or replacing the secret through ops APIs.
Endpoint the partner calls
POST https://connect.intronsoft.com/api/v1/webhooks/partners/{appId}/eventsUnregistered partners can still verify against the landing fallback CONNECT_PARTNER_WEBHOOK_SECRET. Prefer a registered app per partner.
Who can register
Operators and admins. Developers can list apps and events.
If this fails
| Symptom | Cause |
|---|---|
| Register button missing | You are not an operator |
| Partner 401 after rotate | They still sign with the old secret |
| Events land on the wrong workflow | Catalog webhookBind.eventType does not match the payload eventType |
Next: Sign requests