Developers

Webhooks.

Thirty-one events, signed payloads, and a replay button for the afternoon your consumer was down. Subscribe rather than poll — polling a list endpoint on a timer is the fastest route to a 429.

Events

What you can subscribe to

Stand-ups
standup.opened, standup.answered, standup.digest_sent, standup.blocker_raised, standup.blocker_cleared
Sprints
sprint.started, sprint.drift_detected, sprint.ticket_stuck, sprint.forecast_updated, sprint.closed
Docs
doc.created, doc.commented, doc.decision_recorded, doc.approved, doc.archived
Reviews
review.opened, review.sla_breached, review.escalated, review.decided
Roadmaps
roadmap.item_added, roadmap.item_at_risk, roadmap.published
Workspace
member.invited, member.removed, integration.connected, integration.sync_failed
Delivery

How delivery behaves

Signing
HMAC SHA-256 in X-Nexa-Signature, with the timestamp in the signed payload
Retries
Eight attempts with exponential backoff over roughly 24 hours
Ordering
Per-resource ordering guaranteed; global ordering is not
Replay
Any delivery from the last 30 days, by ID, from the dashboard or the CLI
Timeout
Five seconds to a 2xx, or the attempt counts as failed
Payload
JSON, UTC timestamps, resource snapshot plus a diff on update events
FAQ

Questions we get asked

How do we verify a payload?

Compute HMAC SHA-256 over the raw body using your endpoint secret and compare against X-Nexa-Signature in constant time. Reject anything with a timestamp older than five minutes.

What if our endpoint is down for an hour?

Retries run for about 24 hours. After that, replay the missed deliveries by ID — nothing is lost inside the 30-day window.

Are events ordered?

Per resource, yes. Globally, no. Consumers should be idempotent and key on the event ID.

Subscribe instead of polling.