Receive real-time event notifications whenever new projects are posted, proposal drafts are approved by freelancers, conversation messages are sent, or escrow milestones are funded.
Subscriptions can be configured programmatically via POST /api/developer/v1/webhooks/subscriptions or interactively in your Developer Console.
curl -X POST "https://api.botdigit.com/api/developer/v1/webhooks/subscriptions" \
-H "Authorization: Bearer bdt_pat_yourTokenHere" \
-H "Content-Type: application/json" \
-d '{
"target_url": "https://api.yourdomain.com/webhooks/botdigit",
"subscribed_events": ["project.created", "proposal_draft.approved", "milestone.funded"]
}'The response returns a signing secret formatted as whsec_.... Store this secret securely—it is displayed only once.
Every webhook delivery includes a header X-BotDigit-Signature-256 containing the computed hex HMAC signature. Always verify this signature against the raw request body prior to processing events:
import crypto from 'crypto';
export function verifyBotDigitWebhook(rawPayload, signatureHeader, secretKey) {
// Extract hash from "sha256=<hash>"
const expectedHash = signatureHeader.replace('sha256=', '');
const computedHash = crypto
.createHmac('sha256', secretKey)
.update(rawPayload)
.digest('hex');
return crypto.timingSafeEqual(
Buffer.from(computedHash, 'utf8'),
Buffer.from(expectedHash, 'utf8')
);
}To safeguard platform integrity, BotDigit enforces strict network boundary validation on all webhook delivery targets:
| Event Type | Trigger Condition | Payload Summary |
|---|---|---|
| project.created | A new matching marketplace project is published | Project UUID, title, skills, budget range |
| proposal_draft.approved | Freelancer approves an AI-staged proposal draft | Draft UUID, resulting proposal ID, bid amount |
| proposal_draft.rejected | Freelancer rejects or archives a staged draft | Draft UUID, rejection reason |
| milestone.funded | Client deposits escrow funds for a contract milestone | Contract UUID, milestone UUID, amount |
| message.received | Client sends a message in an authorized project thread | Thread UUID, sender ID, content excerpt |