Skip to content
トレカクラウド
Esc
↑↓navigate↵open⌘Jpreview

Register the webhook

Registers the URL notified when stock changes. Notifications carry no stock data: read /inventory/changes when one arrives. Every call returns a new signing secret. The URL must be https and share an origin with one of the app’s redirect URIs.

Notifications are POST url with the body {"type":"inventory.changed","tenantId","connectionId","occurredAt"}. X-TorecaCloud-Signature: v1=<hex> is HMAC-SHA256("<X-TorecaCloud-Timestamp>.<body>") keyed with the secret string. Reject a notification whose timestamp is 300 seconds or more off.

PUT/webhook
Authorization
AuthorizationOAuth2 access token · headerrequired

Authorization code flow (PKCE S256 required). Send resource=https://api.toreca-cloud.com/partner/v1 with the authorization, token and refresh requests. Access tokens last 15 minutes; refresh tokens last 90 days and rotate on every refresh.

Scopes:inventory:read
Request body
requiredapplication/json
urlstring<uri>required
Responses
200

Registered

urlstring<uri>required
secretstringrequired

The signing secret (starts with whsec_). Returned only in this response.

createdAtstring<date-time>required
422

invalid_webhook_url

errorstringrequired

The error code

scopestring

With insufficient_scope, the missing scope

Try it
Server
Authorization
Bodyapplication/json
Request
curl -X PUT 'https://api.toreca-cloud.com/partner/v1/webhook' \
  -H 'Authorization: Bearer YOUR_ACCESS_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "url": "http://example.com"
}'
Response
{
  "url": "http://example.com",
  "secret": "string",
  "createdAt": "2019-08-24T14:15:22Z"
}