API reference
Webhooks
Requests Temper sends to your backend. Every request is signed; see Handling approval webhooks for verification and retries.
Environment events pushed to your backend
POSTyour webhook URL
Sent only if you have set a webhook URL (in the console or with PUT /v1/webhook). The URL is https:// (the certificate is verified against public CAs) or http:// (only for local testing);
redirects are not followed, and a 3xx counts as a failed delivery. Each event is recorded atomically with the change that produced it:
if the change is committed, the event is guaranteed to be sent. A 2xx response counts as delivered; otherwise delivery is retried with exponential backoff starting at 1 minute (at most 1 hour apart), and abandoned if still undelivered after 24 hours.
Request header Temper-Signature: t=<unix seconds>,v1=<hex>, where hex = HMAC-SHA256(webhook secret, "Temper-Event-Id to deduplicate.
Covers events related to the Agent registering schedules / keep-awake from inside the VM (source: agent), and suspension for exceeding a usage limit (environment.limit_exceeded).
Parameters
| Parameter | In | Type | Description |
|---|---|---|---|
Temper-Signaturerequired | header | string | |
Temper-Event-Idrequired | header | string |
Request body application/json · WebhookEvent
| Field | Type | Description |
|---|---|---|
idrequired | string | |
typerequired | "environment.agent_schedule_set" | "environment.agent_schedule_deleted" | "environment.agent_keep_awake" | "environment.agent_keep_awake_released" | "environment.agent_request_rejected" | "environment.limit_exceeded" |
|
createdrequired | string (date-time) | |
environment_idrequired | string | |
datarequired | object | Event details; fields vary by event. Agent-related events carry |
Responses
- 200Any 2xx counts as delivered
Connection changes (created, revoked, refresh failed)
POSTyour webhook URL
Delivery, signing and retries are the same as for environmentEvent.
Parameters
| Parameter | In | Type | Description |
|---|---|---|---|
Temper-Signaturerequired | header | string | |
Temper-Event-Idrequired | header | string |
Request body application/json · ConnectionWebhookEvent
| Field | Type | Description |
|---|---|---|
idrequired | string | |
typerequired | "connection.created" | "connection.revoked" | "connection.error" | |
createdrequired | string (date-time) | |
environment_idrequired | string | Empty string for |
datarequired | object |
|
Responses
- 200Any 2xx counts as delivered
An action needs the end user's approval
POSTyour webhook URL
Delivery, signing and retries are the same as for environmentEvent. Your backend shows summary to the end user and, once it has a decision, POSTs it
to decision_url with the same kind of signature (or calls decideApproval with an API key). If no decision is made before expires_at, the request counts as denied.
If you have not set a webhook URL, this is not sent, and approval requests can only be decided with an API key or left to expire.
Parameters
| Parameter | In | Type | Description |
|---|---|---|---|
Temper-Signaturerequired | header | string | |
Temper-Event-Idrequired | header | string |
Request body application/json · ApprovalRequestedEvent
| Field | Type | Description |
|---|---|---|
idrequired | string | |
typerequired | "approval.requested" | |
createdrequired | string (date-time) | |
environment_idrequired | string | |
datarequired | object |
Responses
- 200Any 2xx counts as delivered
The Agent asks the end user to take over the browser
POSTyour webhook URL
The Agent inside the VM asks the end user to take over when it hits a sign-in or a CAPTCHA (at most once per minute per lease). Your frontend calls takeoverBrowserLease
to get a viewer URL for the end user. Delivery, signing and retries are the same as for environmentEvent.
Parameters
| Parameter | In | Type | Description |
|---|---|---|---|
Temper-Signaturerequired | header | string | |
Temper-Event-Idrequired | header | string |
Request body application/json · TakeoverRequestedEvent
| Field | Type | Description |
|---|---|---|
idrequired | string | |
typerequired | "browser.takeover_requested" | |
createdrequired | string (date-time) | |
environment_idrequired | string | |
datarequired | object |
Responses
- 200Any 2xx counts as delivered