Sign requests
HMAC-SHA256 over the raw body. Idempotent external ids.
Partners prove identity with a signature. There is no API key and no JWT on this path.
Endpoint
POST /api/v1/webhooks/partners/{appId}/events
Content-Type: application/json
X-Partner-Signature: sha256=<hex>
X-Correlation-Id: <optional>{appId} is the inbound app id from Portal Webhooks → Apps.
Payload
{
"eventType": "contact.lead",
"externalId": "lead-1001",
"data": "{\"email\":\"ada@example.com\",\"firstName\":\"Ada\"}"
}eventTypemust match a catalog workflowwebhookBind(contact-lead usescontact.lead).externalIdis unique perappId. Resubmits of the same id return 200 Duplicate and start zero extra runs.datais a JSON string (or object, depending on the partner). Lead PII stays on the event row, not in Temporal input.
Signature
HMAC-SHA256 over the raw request body, hex-encoded. Do not canonicalize or re-serialize JSON before hashing.
BODY='{"eventType":"contact.lead","externalId":"lead-1001","data":"{\"email\":\"ada@example.com\"}"}'
SIG=$(echo -n "$BODY" | openssl dgst -sha256 -hmac "$HMAC_SECRET" | awk '{print $2}')
curl -sS -D - \
-X POST "https://connect.intronsoft.com/api/v1/webhooks/partners/acme/events" \
-H "Content-Type: application/json" \
-H "X-Partner-Signature: sha256=$SIG" \
-d "$BODY"Responses
| HTTP | Portal chip | Meaning |
|---|---|---|
| 202 | Accepted | First accept. Workflow start is retryable under the response correlation id |
| 200 | Duplicate | Same (appId, externalId) already accepted |
| 401 | — | Signature missing or does not match |
The workflow id is the accept correlationId. After ten failed starts the scheduler skips the row. Operators Retry start from Events.
Try it
Interactive reference: APIs → Experience → Contact lead inbound.
If this fails
| Symptom | Cause |
|---|---|
| 401 | Body sent to curl is not the same bytes you hashed (echo added a newline, or a JSON library reordered keys) |
| 202 but empty Events | You posted to a different host than the portal’s platform |
| Duplicate when you expected a new lead | Reuse of externalId — mint a new one per real-world event |
| Second workflow for the same lead | You changed externalId; Connect will start again |
Next: Inbound events · Contact leads