Webhooks

Signed callbacks when bulk jobs finish.

Register a webhook URL in the dashboard to be notified when a bulk job completes, instead of polling.

Verification

Every webhook request is signed. The signature travels in the X-EVA-Signature header as an HMAC of the request body using your webhook signing secret (shown when you create the webhook). Always verify it before acting on the payload, and use HTTPS endpoints only.

Webhook URLs are validated against SSRF: internal and private network addresses are refused.

Payload

The payload describes the completed job: job id, status, row counts by verdict, and a link to fetch full results over the API. Exact fields are shown with an example payload in the dashboard webhook editor.