Endpoint
Request
string
required
application/jsonstring
required
Lowercase hexadecimal HMAC-SHA256 of the exact raw request body bytes, keyed with the
webhook’s signing secret. No prefix (send
3f1a…, not sha256=3f1a…).JSON
required
UTF-8 JSON, at most 64 KB (65,536 bytes). Any JSON is accepted; bodies that match the
proposal contract (
proposal.created, proposal.won, client.created) are mapped natively.
See Incoming webhooks for the field rules.Response
Signature verification happens before the body is parsed, and uses a constant-time comparison.
Deduplication and retries
Hive deduplicates on the SHA-256 of the raw body, per webhook. Retrying the same bytes after a timeout is safe: you get202 with "deduplicated": true, and the event is processed once. To
send two genuinely separate events with the same content, make the bodies differ — for example
with a distinct eventId.
Examples
Security notes
- Treat the signing secret like a password. Store it in your automation tool’s secret storage, never in source control.
- Hive stores only a sealed copy of the secret and cannot show it again. To rotate, create a new webhook, switch your sender to it, then delete the old one.
- Event content is treated as untrusted input: every field is bounded and validated before it reaches the Business Brain.
Related
Incoming webhooks
Create a webhook and the event contract.
Developer overview
Everything you can build against.