Total Access Docs
Openapi

Outbound webhook delivery

TotalAccess delivers webhook events to your configured endpoint URL. The payload is an envelope containing the event name, timestamp, and event data. ### Authentication Depending on the webhook configuration, one of these auth methods is used: - **HMAC** — `X-TA-Signature` header with HMAC-SHA256 of the raw body - **Bearer** — `Authorization: Bearer <token>` header - **Basic** — `Authorization: Basic <base64>` header - **None** — No authentication ### Idempotency Each delivery includes an `Idempotency-Key` header (event UUID) so receivers can deduplicate redelivered events. ### Retry Policy Failed deliveries are retried with exponential backoff. The retry count and timeout are configurable per webhook.

TotalAccess delivers webhook events to your configured endpoint URL. The payload is an envelope containing the event name, timestamp, and event data.

Authentication

Depending on the webhook configuration, one of these auth methods is used:

  • HMACX-TA-Signature header with HMAC-SHA256 of the raw body
  • BearerAuthorization: Bearer <token> header
  • BasicAuthorization: Basic <base64> header
  • None — No authentication

Idempotency

Each delivery includes an Idempotency-Key header (event UUID) so receivers can deduplicate redelivered events.

Retry Policy

Failed deliveries are retried with exponential backoff. The retry count and timeout are configurable per webhook.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

Example Requests

POST/outboundWebhook

POST/outboundWebhook

POST/outboundWebhook