s.id Logo
s.id
डेवलपर प्लेटफ़ॉर्म

Webhooks

आपके HTTPS endpoint पर रियल-टाइम event डिलीवरी।

अवलोकन

Dashboard → Developer → Webhooks में एक सार्वजनिक HTTPS endpoint रजिस्टर करें। जब कोई subscribed event होता है तो s.id आपके URL पर signed JSON payload POST करेगा। विफल deliveries (non-2xx या timeout) को अधिकतम 3 बार, 0 सेकंड, 5 सेकंड और 30 सेकंड की देरी के साथ फिर से कोशिश की जाती है।

उपलब्ध Events

link.createdFired when a new link is created
link.updatedFired when a link's URL or title is changed
link.archivedFired when a link is archived
link.clickedFired on each redirect (per-click event)
microsite.publishedFired when a microsite is published
qr.scannedFired when a QR code is scanned

Payload संरचना

प्रत्येक webhook POST में event name, संबंधित resource और UTC timestamp के साथ JSON body होती है।

{
  "event": "link.created",
  "link": {
    "id": 123,
    "short": "mylink",
    "short_url": "https://s.id/mylink",
    "long_url": "https://example.com/long-url",
    "title": "My Link",
    "created": "2026-06-22T10:00:00Z"
  },
  "timestamp": "2026-06-22T10:00:00Z"
}

Signatures सत्यापित करना

प्रत्येक delivery में X-SID-Signature: sha256=<hex> header शामिल है। अपने webhook secret का उपयोग करके raw request body का HMAC-SHA256 compute करें और timing-safe equality से compare करें।

event प्रोसेस करने से पहले हमेशा signature सत्यापित करें। HMAC verify किए बिना payload पर कभी भरोसा न करें।

Node.js

const crypto = require('crypto');

function verifySignature(secret, rawBody, sigHeader) {
  const expected = 'sha256=' +
    crypto.createHmac('sha256', secret).update(rawBody).digest('hex');
  return crypto.timingSafeEqual(
    Buffer.from(sigHeader),
    Buffer.from(expected),
  );
}

Go

func verifySignature(secret, body []byte, sig string) bool {
  mac := hmac.New(sha256.New, secret)
  mac.Write(body)
  expected := "sha256=" + hex.EncodeToString(mac.Sum(nil))
  return hmac.Equal([]byte(sig), []byte(expected))
}

सेटअप

  1. 1Dashboard → Developer → Webhooks पर जाएं और Add Webhook क्लिक करें।
  2. 2अपना HTTPS endpoint URL दर्ज करें और जिन events को subscribe करना चाहते हैं उन्हें चुनें।
  3. 3Webhook secret कॉपी करें — यह केवल एक बार दिखाया जाता है।
  4. 4अपने server में, processing से पहले X-SID-Signature header सत्यापित करें।
  5. 510 सेकंड के भीतर HTTP 2xx लौटाएं। विफल deliveries को अधिकतम 3 बार retry किया जाता है; लगातार 5 विफल deliveries के बाद webhook स्वतः निष्क्रिय हो जाता है।