Set up a webhook
name (1–50 chars), url (must be HTTPS), subscribedEvents (≥ 1). The response includes a signing secret (whsec_...). Store it. You’ll verify every payload against it.
Manage endpoints (create, update, delete, test) via the API or the dashboard.
Events
Payload
job.completed payload includes the unified output object. The data field has the structured answer for analysis jobs, file.url is a signed, time-limited URL, and files lists every produced file. Read Job output for the full shape, the File type, and the four output patterns.
output shape is identical for every job type. A data-only job (such as extract.metadata) carries its answer in output.data with file null and files empty. A stream job carries the manifest as output.file and every segment in output.files. See Job output for each pattern.
For job.failed, the payload carries error instead of output. The error matches the GET /jobs error shape: code, message, detail (the process stderr tail, or null), and retryable.
Verify the signature
The signature is HMAC-SHA256 over{timestamp}.{body} using your webhook secret. Timestamp-prefixed to prevent replays.
Secret rotation
Rotation has a 24-hour window. During it, Rendobar sends bothX-Rendobar-Signature (new secret) and X-Rendobar-Signature-Previous (old). Verify against either.
SSRF protection
URLs must be HTTPS. Delivery to private/reserved ranges (10.x, 172.16-31.x, 192.168.x, 127.x, ::1) is blocked.
Retries
If your endpoint doesn’t return2xx within 10 seconds, Rendobar retries:
After three failures the delivery is marked failed. Inspect history:
Best practices
- Return 200 fast. Process asynchronously. Long handlers trigger retries → duplicate deliveries.
- Deduplicate on
X-Rendobar-DeliveryorjobId. Same event can arrive more than once. - Verify every signature before reading the body.
See also
- Job output: the canonical
outputanderrorshape this payload carries - Job lifecycle
- FFmpeg
- Error codes
- MCP: alternative push channel for AI agents
Related
- Job lifecycle: what each status means before
job.completedfires - Error codes: codes you’ll see inside
job.failedpayloads - FFmpeg: the job type that drives most webhook traffic
- MCP overview: alternative push channel for AI agent clients
- Changelog: webhook payload changes and new events