Get the webhook signing secret
Returns the tenant’s webhook-signing secret, generating one on first call if none exists yet. Use it to verify the X-Webhook-Signature header (HMAC-SHA256 over the raw request body) on incoming call.completed / batch.completed webhooks. Unlike an API key, this isn’t shown once and thrown away: it authenticates payloads we send to you, not requests you send to us, so it’s safe to fetch again any time you need it.
Verifying a webhook’s signature confirms that a request claiming to be a
call.completed or batch.completed notification genuinely came from
us, and that its contents weren’t altered in transit. Every webhook is
signed with HMAC-SHA256 over the raw bytes of the request body, using
your tenant’s webhook secret, and the resulting signature is sent in the
X-Webhook-Signature header.
To verify a webhook, compute the same HMAC-SHA256 signature yourself
over the exact raw bytes your server received, not a version you’ve
parsed into an object and re-serialized, since re-serializing can
produce a different byte sequence than what was originally signed even
for a genuine, unmodified payload, which would make a valid signature
appear invalid. Compare your computed signature to the
X-Webhook-Signature header using a constant-time comparison function,
such as hmac.compare_digest in Python, rather than a plain equality
check: an ordinary comparison can leak timing information that makes a
correct signature easier to guess one byte at a time.
Authorizations
A long-lived, privileged API key (ek_... prefix), minted once from the dashboard. Intended for trusted server-side use only; never expose it in client-side code. Send as Authorization: Bearer ek_.... Required by every Calls, Batches, Agents, Tools, MCP Servers, Documents, and Realtime route.
Response
Successful Response