API reference · Platform
Webhooks
Signed events when renders land and flow runs end — what Zapier, Make and n8n subscribe to.
An endpoint gets a signed POST for each event it listens to: image.generation.succeeded / image.generation.failed, video.generation.succeeded / video.generation.failed, flow.run.succeeded / flow.run.failed (a flow run ended) and flow.run.waiting (a run waits on a post for someone's click). Create endpoints here or in the dashboard (Developers › Webhooks); flow_id narrows the flow events to one flow. Up to 25 per workspace. Managing them takes the webhooks:manage role (owners and admins by default).
REST hooks. Zapier, Make and n8n subscribe when a Zap, a scenario or a workflow with an eroq trigger is turned on (POST /v1/webhooks) and unsubscribe when it is turned off (DELETE /v1/webhooks/{id}). An endpoint that answers 410 Gone is deleted. GET /v1/webhooks/samples?event=… gives the last few real events of a type (or one example): the sample a trigger shows before the first real event fires.
Every delivery is { "id": "evt_…", "type": "…", "created": <unix>, "data": { … } } with the header eroq-signature: t=<unix>,v1=<hex>, where v1 = HMAC-SHA256(secret, <t>.<raw body>). Rebuild that string from the raw body, compare in constant time, and refuse timestamps older than 5 minutes. One attempt with a 10-second budget: answer 2xx at once and do the work after.
A flow.run.* event carries flow (id, name), run (id, status, source, credits, startedAt, finishedAt, inputs) and outputs: each render (kind, url signed for 7 days, creationId) and each text Clap wrote, by step; failure (step, nodeId, type, message) on a failed run, waiting on a run that waits on a post. A *.generation.* event carries the job id, model, content_type, result_url (signed for 7 days, permanent with store: true) and library_id (or error.code when it failed, already refunded). A render finishes when it is read: poll its job, or put it in a flow, for the event to come at once.
Endpoints
Select a verb to load its request, playground and response.
The workspace's endpoints and subscriptions, newest first — never their secrets.
Subscribe an endpoint (201). The signing secret is answered once: store it.
An https URL, not a private or internal host.
One or more of image.generation.succeeded, image.generation.failed, video.generation.succeeded, video.generation.failed, flow.run.succeeded, flow.run.failed, flow.run.waiting.
Only this flow's flow.run.* events. 404 flow_not_found for a flow outside the workspace.
Unsubscribe: no event reaches that URL again. Idempotent: an endpoint already gone answers deleted: false.
Up to 3 recent events of a type, exactly as an endpoint would have received them, or one example when there is none yet.
curl https://eroq.ai/v1/webhooks \
-H "Authorization: Bearer $EROQ_API_KEY"Response
{
"object": "list",
"webhooks": [{
"object": "webhook", "id": "c2f1…", "url": "https://hooks.zapier.com/hooks/standard/…",
"events": ["flow.run.succeeded"], "flowId": "1e45…", "enabled": true,
"lastDeliveryAt": "2026-10-09T18:06:02Z", "lastStatus": 200, "createdAt": "2026-10-09T18:02:11Z"
}]
}