Receive real-time event notifications from the Airfree platform, verify their signatures, and process them reliably.
Webhooks push platform events to your endpoint as they happen, so you avoid polling. You register an HTTPS endpoint, subscribe to the event types you care about, and the platform delivers a signed JSON payload for each event.
Subscribe
Register an endpoint and the events you want. Delivery is per tenant and respects the same access model as the rest of the platform.
curl -X POST https://airfree.au/api/v1/webhooks/subscriptions \
-H "Authorization: Bearer $AIRFREE_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"url": "https://your-app.example/hooks/airfree",
"events": ["cadastre.parcel.registered", "eo.scene.published"]
}'Verify the signature
Each delivery includes an HMAC signature header computed over the raw request body with your subscription’s secret. Recompute it and compare in constant time before trusting the payload — never process an unverified webhook.
X-Airfree-Signature: sha256=<hex hmac of the raw body>Process reliably
- Respond 2xx quickly, then do work asynchronously — slow handlers cause retries.
- Deduplicate on the event id: deliveries are at-least-once, so the same event can arrive twice.
- Failed deliveries are retried with back-off; return 2xx only once you have durably accepted the event.