Webhooks

Events: conversation.created, conversation.updated, message.created, message.received, message.replied, customer.created, handoff.requested, handoff.completed.

Create with POST /api/v1/webhooks {"url":"https://...","events":["message.replied"]}. The signing secret is returned once.

Each delivery has the header X-Buejee-Signature: t=UNIX,v1=HEX where HEX = HMAC-SHA256(secret, "t.rawBody"). Verify it and reject timestamps older than 5 minutes.

$expected = hash_hmac('sha256', $t . '.' . $rawBody, $secret);
if (!hash_equals($expected, $v1)) { http_response_code(401); exit; }

Endpoints must be https on port 443 and resolve to a public IP. Failed deliveries are retried by cron.