Webhooks
Two directions, both HMAC-signed — no polling required.
Outbound: we call you
Register an endpoint in the portal (Developer → Webhooks) and subscribe to events
such as run.completed, run.waiting_approval and workflow.run.finished.
Each delivery carries:
X-AI-Platform-Timestamp: 1787140000
X-AI-Platform-Signature: hex(hmac_sha256(secret, "{timestamp}.{raw_body}"))
Verify by recomputing the signature over the raw body with your endpoint's secret and comparing constant-time; reject timestamps older than 300 seconds. Failed deliveries retry five times with exponential backoff, then land in a dead-letter list you can inspect in the portal.
Inbound: you trigger a workflow
A workflow with webhooks enabled accepts:
POST https://platform.senaiy.ai/v1/workflows/{code}/webhook
signed the same way (shared secret from the workflow's settings), with an optional source-IP allowlist. Unconfigured webhooks fail closed — a workflow can never be triggered by an unsigned call.