Lifecycle webhooks

Delivery status

Configure an HTTPS endpoint with PUT /v1/integrations/apps/{client_id}/webhook and read it with GET on the same route. The signing secret is returned once. Reconfiguration cancels pending and failed events from the old generation. POST on /webhook/test returns 202 with a queued event ID; inspect /webhook/events for actual delivery status. Delivery requires the separately running Pura webhook worker. You can also configure the URL, replace the signing secret, queue a test, inspect deliveries and retry or skip failed events from Integrations → your app → Manage webhooks in the console.

Current integration contract

Use OAuth to connect and GET /v1/integrations/usage with usage:read to read shared limits. Inference errors remain authoritative for access. Future lifecycle notifications will never include the internal virtual key or encrypted copies of it. Current outbox event names are integration.connected and integration.revoked; revocation data identifies user_disconnected or app_suspended. Events contain user identity and scope/reason metadata, never tokens or account keys. Subscription.updated carries status, plan, period, paid budget snapshot and revision. Subscription.ended signals canceled, unpaid or incomplete_expired. Repeated unchanged Stripe state does not duplicate notifications. A newly consented connection receives its current subscription snapshot. Match webhook user.pura_user_id to the pura_user_id saved from your server-side OAuth exchange; do not trust a browser-submitted ID.

Release requirements

SDK helpers verify raw-body HMAC, a 300-second replay window and the integration ID. Use a persistent transactional process-once store: delivery is at least once. The worker retries up to eight times with exponential delays, preserves event ID/body and signs a fresh timestamp. A failed event blocks later events for that app. POST /webhook/events/{event_id}/recover with action retry or skip recovers failed events; skipping creates a sequence gap. TLS hostname verification, public DNS address checks and connection IP pinning are implemented. Live deployment and PostgreSQL concurrent-worker verification remain pending.