Outbound & sales

Webhooks

Get notified in your own systems when things change in CorvaneOS.

Events

EventSent when
feedback.createdNew feedback arrives.
feedback.updatedFeedback status, owner or analysis changes.
issue.createdAn issue is created.
issue.resolvedAn issue is resolved.
review.createdA new review arrives.

Payload

POST to your endpoint
{
  "id": "5f0c…",
  "event": "feedback.created",
  "createdAt": "2026-09-29T10:12:00.000Z",
  "data": { "id": "7b1c…", "message": "…", "rating": 2, "source": "in_app", "customerId": "d93e…" }
}

Verify the signature

Each request carries X-CorvaneOS-Event, X-CorvaneOS-Timestamp and X-CorvaneOS-Signature: sha256=<hex>, an HMAC-SHA256 of <timestamp>.<raw body> using your endpoint secret.

Node.js
import crypto from "node:crypto";

function verify(req, rawBody, secret) {
  const ts = req.headers["x-corvaneos-timestamp"];
  const expected = "sha256=" + crypto.createHmac("sha256", secret).update(`${ts}.${rawBody}`).digest("hex");
  return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(req.headers["x-corvaneos-signature"]));
}

Delivery

Endpoints must be public HTTPS URLs. Failed deliveries are retried up to 3 times (after 1 and 4 seconds). Respond with any 2xx status to acknowledge.