DOCUMENTATION

React to the outcome.

Verify signed events before processing them.

Full API reference and interactive request explorer →

Register a destination

Contact support to arrange signed event destination setup and approval of your HTTPS hostname. Destination configuration is not available in the PWA. Keep the signing secret secure and contact support to disable a destination.

Events

message.received, message.sent, message.delivered, message.failed, ai_call.started, ai_call.completed, and ai_call.failed.

Verify the raw payload

Read x-ze-timestamp (Unix milliseconds) and x-ze-signature (hex). Calculate HMAC-SHA256(secret, timestamp + a full stop + the unmodified raw JSON body). Compare in constant time and reject timestamps more than five minutes from your clock. x-ze-event-id identifies retries. Fetch message details using your separately scoped API key.

Delivery semantics

Events may arrive more than once and out of order. Deduplicate by event ID. Failed deliveries retry with backoff for up to 24 hours.

Pilot access requires verified organisation configuration. Never expose a live API key in frontend code.

View the versioned OpenAPI contract