Authorization token, and an optional signing secret), then attach it to an
export. Ontoto sends the payload as the raw request body of a POST or PUT
request.
The export system supports the following payloads:
- File exports send the generated file as the body, with its path in
X-Ontoto-File-Path. - Events send a small JSON body produced by the export function itself, with no file involved. Events suit a fetch-on-notify integration, e.g. an export configured to run when a device transmits can tell you when new data is received, so your backend can fetch the readings immediately through the sensor data API.
standard-webhooks library in most
languages instead of implementing the validation yourself.
Request headers
Every delivery carries a common envelope:
Any static headers configured on the endpoint (for example
Authorization)
are sent as-is on every request. Individual consumers add their own headers on
top of the envelope:
Receivers should ignore unrecognised headers and unrecognised
webhook-signature versions; new consumers and scheme versions add entries
without removing existing ones.
The webhook-id of each export delivery is also logged in the export generation history available
in the Exports page.
Verifying the signature
The signing secret shown when you configure the endpoint is in the Standard Webhookswhsec_<base64> format. The easiest way to verify is a
standard-webhooks library:
- Read
webhook-timestampand check it is within your replay window (the reference libraries default to 5 minutes of your server clock). - Base64-decode the secret after the
whsec_prefix; those bytes are the HMAC key. - Compute the base64 HMAC-SHA256 over the UTF-8 bytes of
{webhook-id}.{webhook-timestamp}.{raw body}. Use the raw body bytes exactly as received. - Compare against each
v1,<signature>entry inwebhook-signatureusing a constant-time comparison; accept if any entry matches.
Why the replay window matters
The signature proves who sent a request and that it was not altered, but not when; a captured signed request would otherwise pass verification forever if resent. Because the timestamp is inside the signed content, an attacker can neither replay an old request outside your window nor freshen its timestamp without breaking the signature. Usewebhook-id to deduplicate any
replays within the window.
Test requests
The Send test request button in the endpoint dialog sends a small payload (by default the JSON body{ "test": true }) through the same pipeline:
static headers, envelope headers, and signature are identical to a real
delivery, so you can use it to verify connectivity, authentication, and your
signature implementation end to end.
Responding
Respond with any2xx status to acknowledge a delivery. Any other status (or
a timeout, currently 30 seconds) is treated as a failed delivery.