Trigger a Webhook from Streaming Hub
Use this endpoint as the endpoint of a Streaming Hub webhook subscription. It triggers the same workflow execution as POST /v1/webhooks/{path}. Only the authentication is different: this route takes no Bearer token. Flowker verifies an HMAC-v1 signature over the raw request body with the tenant’s inbound signing secret, which the deployment keeps in its secrets backend. The signing secret of the subscription and the stored secret must be the same value. Flowker refuses a legacy sha256= (v0) signature, because v0 has no replay protection. Flowker serves this route only when the deployment turns on the signed Streaming Hub ingress. It is off by default.
Headers
HMAC-v1 signature over the raw body, in the form v1,sha256=<hex>. The hex value is the HMAC-SHA256 of v1:<X-Webhook-Timestamp>.<raw body>, keyed with the tenant's inbound signing secret. During a signing-secret rotation, the header repeats once for each active secret, two values at most. Flowker accepts the delivery when one value verifies.
Unix time in seconds, the same value the signature covers. Flowker rejects a timestamp outside the freshness window, five minutes by default, even when the signature is correct.
Tenant that owns the delivery. Flowker uses it to select the signing secret to check. A valid signature confirms it.
Streaming Hub event ID. Flowker uses it as the replay key for each workflow. A delivery that repeats an event ID returns the first execution and does not run the workflow again.
Delivery-attempt ID, recorded for correlation. It changes on every retry of the same event.
Optional idempotency key. A repeated key returns the prior execution. When the delivery carries X-Lerian-Event-Id, the event ID takes precedence.
Path Parameters
Webhook path registered by a workflow. Supports nested paths with multiple segments at runtime. Forward slashes within the path must be percent-encoded as %2F per RFC 3986/OpenAPI 3.1 (for example, use orders%2Fpaid for orders/paid).
Body
The delivered event, byte for byte. The signature covers these bytes, so they must not be re-encoded in transit. Maximum size is 1 MB.
Event payload. When the webhook trigger defines an input contract, Flowker validates the payload against it.
Response
The workflow finished inside the synchronous window. The body carries the final business results.
Timestamp when the execution finished.
"2026-03-17T14:35:12Z"
Unique identifier of the execution.
"f7e6d5c4-b3a2-1098-7654-321fedcba098"
Aggregated output from the last step or the workflow's final result.
Timestamp when the execution started.
"2026-03-17T14:35:00Z"
Final status of the execution.
"completed"
Ordered list of results for each step executed.
ID of the workflow that was executed.
"a1b2c3d4-e5f6-7890-abcd-ef1234567890"

