Register the webhook
Registers the URL notified when stock changes. Notifications carry no stock data: read /inventory/changes when one arrives. Every call returns a new signing secret. The URL must be https and share an origin with one of the app’s redirect URIs.
Notifications are POST url with the body {"type":"inventory.changed","tenantId","connectionId","occurredAt"}. X-TorecaCloud-Signature: v1=<hex> is HMAC-SHA256("<X-TorecaCloud-Timestamp>.<body>") keyed with the secret string. Reject a notification whose timestamp is 300 seconds or more off.
/webhookAuthorizationOAuth2 access token · headerrequiredAuthorization code flow (PKCE S256 required). Send resource=https://api.toreca-cloud.com/partner/v1 with the authorization, token and refresh requests. Access tokens last 15 minutes; refresh tokens last 90 days and rotate on every refresh.
inventory:readapplication/jsonurlstring<uri>requiredRegistered
urlstring<uri>requiredsecretstringrequiredThe signing secret (starts with whsec_). Returned only in this response.
createdAtstring<date-time>requiredinvalid_webhook_url
errorstringrequiredThe error code
scopestringWith insufficient_scope, the missing scope

