Event Streaming

Outbound Webhooks Guide

Receive real-time event notifications whenever new projects are posted, proposal drafts are approved by freelancers, conversation messages are sent, or escrow milestones are funded.

Registering a Webhook Subscription

Subscriptions can be configured programmatically via POST /api/developer/v1/webhooks/subscriptions or interactively in your Developer Console.

curl -X POST "https://api.botdigit.com/api/developer/v1/webhooks/subscriptions" \
  -H "Authorization: Bearer bdt_pat_yourTokenHere" \
  -H "Content-Type: application/json" \
  -d '{
    "target_url": "https://api.yourdomain.com/webhooks/botdigit",
    "subscribed_events": ["project.created", "proposal_draft.approved", "milestone.funded"]
  }'

The response returns a signing secret formatted as whsec_.... Store this secret securely—it is displayed only once.

HMAC-SHA256 Signature Verification

Every webhook delivery includes a header X-BotDigit-Signature-256 containing the computed hex HMAC signature. Always verify this signature against the raw request body prior to processing events:

import crypto from 'crypto';

export function verifyBotDigitWebhook(rawPayload, signatureHeader, secretKey) {
  // Extract hash from "sha256=<hash>"
  const expectedHash = signatureHeader.replace('sha256=', '');
  
  const computedHash = crypto
    .createHmac('sha256', secretKey)
    .update(rawPayload)
    .digest('hex');

  return crypto.timingSafeEqual(
    Buffer.from(computedHash, 'utf8'),
    Buffer.from(expectedHash, 'utf8')
  );
}

Webhook Endpoint Requirements & SSRF Protection

To safeguard platform integrity, BotDigit enforces strict network boundary validation on all webhook delivery targets:

  • Public HTTPS Required: Production webhooks must resolve to publicly reachable HTTPS endpoints.
  • Restricted Subnets Blocked: Target domains that resolve to loopback addresses, private networks (RFC 1918), or cloud metadata services are automatically blocked prior to dispatch.
  • Sensitive Ports Denied: Webhook deliveries to administrative or database ports are rejected.
  • Zero Redirect Following: The webhook dispatcher enforces strict no-redirect policies to eliminate DNS-rebinding and hop-based SSRF vectors.

Supported Event Types

Event TypeTrigger ConditionPayload Summary
project.createdA new matching marketplace project is publishedProject UUID, title, skills, budget range
proposal_draft.approvedFreelancer approves an AI-staged proposal draftDraft UUID, resulting proposal ID, bid amount
proposal_draft.rejectedFreelancer rejects or archives a staged draftDraft UUID, rejection reason
milestone.fundedClient deposits escrow funds for a contract milestoneContract UUID, milestone UUID, amount
message.receivedClient sends a message in an authorized project threadThread UUID, sender ID, content excerpt
Was this page helpful?
HomeJobs
Get Started
ExploreSign In