date-time when a webhook was created.
date-time when a webhook was updated.
A URL that is triggered by an event, for example, a file upload. A target URL MUST be unique for each project — event type combination.
Marks a subscription as either active or not, defaults to true, otherwise false.
Optional HMAC/SHA-256 secret that, if set, will be used to
calculate signatures for the webhook payloads sent to the target_url.
Calculated signature will be sent to the target_url as a value of the X-Uc-Signature HTTP
header. The header will have the following format: X-Uc-Signature: v1=<HMAC-SHA256-HEX-DIGEST>.
See Secure Webhooks for details.
Every request made to https://api.uploadcare.com/ MUST be signed. HTTPS SHOULD be used with any authorization scheme.
Requests MUST contain the Authorization header defining auth-scheme and auth-param: Authorization: auth-scheme auth-param.
Every request MUST contain the Accept header identifying the REST API version: Accept: application/vnd.uploadcare-v0.7+json.
There are two available authorization schemes:
Uploadcare, a scheme where a signature, not your Secret API Key MUST be specified. Signatures SHOULD be generated on backend.Uploadcare.Simple, a simple scheme where your Secret API Key MUST be specified in every request’s auth-param.