Skip to main content
Callbacks aren’t live yet. This page documents the design so you can plan for it; nothing below is callable today. Until it ships, poll GET /v1/auth/test periodically to detect a disconnect (401 token_revoked) instead of waiting for app.uninstalled.
When callbacks ship, Workchats will POST signed events to your App’s registered callback URL — one URL per App, shared across every company that installs it.

Envelope

id is unique per event, so a retried delivery is safe to ignore if you’ve already processed that id.

Event types

Signature verification

Every callback carries:
<hex> is HMAC-SHA256(signing_secret, "<timestamp>.<raw request body>"), hex-encoded. Verify against the raw request body — parsing to JSON and re-serializing before checking the signature will not match.
Node
Reject anything where the signature doesn’t match, or where the timestamp is more than 5 minutes old. During a signing-secret rotation, Workchats sends two comma-separated values — v1=<new>,v1=<old> — for 24 hours, so check every value in the header rather than only the first.

Delivery and retries

HTTPS only, TLS 1.2+, no redirects followed. A response other than 2xx within 3 seconds counts as a failure and is retried at 1 minute, 5 minutes, and 30 minutes, with the same event id. Respond 2xx as soon as you’ve durably queued the event — don’t do slow work in the request path before responding.