Register a destination
Contact support to arrange signed event destination setup and approval of your HTTPS hostname. Destination configuration is not available in the PWA. Keep the signing secret secure and contact support to disable a destination.
Events
message.received, message.sent, message.delivered, message.failed, ai_call.started, ai_call.completed, and ai_call.failed.
Verify the raw payload
Read x-ze-timestamp (Unix milliseconds) and x-ze-signature (hex). Calculate HMAC-SHA256(secret, timestamp + a full stop + the unmodified raw JSON body). Compare in constant time and reject timestamps more than five minutes from your clock. x-ze-event-id identifies retries. Fetch message details using your separately scoped API key.
Delivery semantics
Events may arrive more than once and out of order. Deduplicate by event ID. Failed deliveries retry with backoff for up to 24 hours.
Pilot access requires verified organisation configuration. Never expose a live API key in frontend code.