API reference · Platform

Webhooks

Signed events when renders land and flow runs end — what Zapier, Make and n8n subscribe to.

GETPOSTDELETE/v1/webhooksfree

An endpoint gets a signed POST for each event it listens to: image.generation.succeeded / image.generation.failed, video.generation.succeeded / video.generation.failed, flow.run.succeeded / flow.run.failed (a flow run ended) and flow.run.waiting (a run waits on a post for someone's click). Create endpoints here or in the dashboard (Developers › Webhooks); flow_id narrows the flow events to one flow. Up to 25 per workspace. Managing them takes the webhooks:manage role (owners and admins by default).

REST hooks. Zapier, Make and n8n subscribe when a Zap, a scenario or a workflow with an eroq trigger is turned on (POST /v1/webhooks) and unsubscribe when it is turned off (DELETE /v1/webhooks/{id}). An endpoint that answers 410 Gone is deleted. GET /v1/webhooks/samples?event=… gives the last few real events of a type (or one example): the sample a trigger shows before the first real event fires.

Every delivery is { "id": "evt_…", "type": "…", "created": <unix>, "data": { … } } with the header eroq-signature: t=<unix>,v1=<hex>, where v1 = HMAC-SHA256(secret, <t>.<raw body>). Rebuild that string from the raw body, compare in constant time, and refuse timestamps older than 5 minutes. One attempt with a 10-second budget: answer 2xx at once and do the work after.

A flow.run.* event carries flow (id, name), run (id, status, source, credits, startedAt, finishedAt, inputs) and outputs: each render (kind, url signed for 7 days, creationId) and each text Clap wrote, by step; failure (step, nodeId, type, message) on a failed run, waiting on a run that waits on a post. A *.generation.* event carries the job id, model, content_type, result_url (signed for 7 days, permanent with store: true) and library_id (or error.code when it failed, already refunded). A render finishes when it is read: poll its job, or put it in a flow, for the event to come at once.

Endpoints

Select a verb to load its request, playground and response.

GET/v1/webhooksshown

The workspace's endpoints and subscriptions, newest first — never their secrets.

POST/v1/webhooks

Subscribe an endpoint (201). The signing secret is answered once: store it.

urlstringrequired

An https URL, not a private or internal host.

eventsarrayrequired

One or more of image.generation.succeeded, image.generation.failed, video.generation.succeeded, video.generation.failed, flow.run.succeeded, flow.run.failed, flow.run.waiting.

flow_idstring

Only this flow's flow.run.* events. 404 flow_not_found for a flow outside the workspace.

DELETE/v1/webhooks/{id}

Unsubscribe: no event reaches that URL again. Idempotent: an endpoint already gone answers deleted: false.

GET/v1/webhooks/samples

Up to 3 recent events of a type, exactly as an endpoint would have received them, or one example when there is none yet.

curl https://eroq.ai/v1/webhooks \
  -H "Authorization: Bearer $EROQ_API_KEY"
/v1/webhooks
→ GET /v1/webhooks
Press run — this replays a real exchange from the docs' own data. No key, no request, no charge.

Response

200 · application/json
{
  "object": "list",
  "webhooks": [{
    "object": "webhook", "id": "c2f1…", "url": "https://hooks.zapier.com/hooks/standard/…",
    "events": ["flow.run.succeeded"], "flowId": "1e45…", "enabled": true,
    "lastDeliveryAt": "2026-10-09T18:06:02Z", "lastStatus": 200, "createdAt": "2026-10-09T18:02:11Z"
  }]
}