callback_url parameter of your request.
The event object
string
The unique identifier of the event.
string
The type of the event, possible values are:
object
The payload of the event, whose structure depends on the event type.
RFC3339 date string
The timestamp of the event creation.
How to set up your Webhook
To start receiving webhook events in your app, create and register a webhook endpoint by following the steps below. You can register and create one endpoint to handle several different event types at once, or set up individual endpoints for specific events.1
Implement the handler
Develop a webhook endpoint function to receive event data POST requests.
2
Pass the URL
Add your webhook endpoint URL to your Verification requests to start
receiving events.
3
Return OK
Return a
200 OK HTTP response to the POST request to acknowledge receipt
of the event. If you don’t, Prelude will retry sending the event with
exponential backoff for up to 2 weeks. Retries are spaced progressively
further apart (1 min, 2 min, 4 min, … up to 12 hours) to allow your
endpoint time to recover if it’s temporarily down.Delivery Statuses
When we receive a delivery status from the carrier, we send a webhook event with theverify.delivery_status type. The status field in the payload indicates the current state of the message delivery.
Here are the possible status values:
Delivery statuses are indicative, but they may not always be fully reliable. Depending on the market, a “delivered” confirmation can indicate delivery to the mobile network operator, the cell tower, or — in some cases — the end user’s handset.
Cost reconciliation can take up to 15 minutes. During this window, the billed amount may not yet reflect the final cost of the message.
Security
Prelude’s webhooks support the following security features:Webhook Signature
To ensure the authenticity of the webhook events, we use a signature mechanism. The signature is a base64 URL-encoded RSASSA-PSS on the SHA256 hash of the payload. The signature is sent as a string prefixed withrsassa-pss-sha256= in the X-Webhook-Signature header of each request to your webhook endpoint.
To enable the webhook signature, go to the Prelude dashboard in the Verify API->Configure->Webhooks section and generate a webhook signing key for your application.
You can then verify the signature of the webhook events in your webhook endpoint and process the event only if the signature is valid.
The same signing key is used for both the Verify and Notify APIs.