temperDocs
Menu

API reference

Webhooks

Requests Temper sends to your backend. Every request is signed; see Handling approval webhooks for verification and retries.

Environment events pushed to your backend

POSTyour webhook URL

Sent only if you have set a webhook URL (in the console or with PUT /v1/webhook). The URL is https:// (the certificate is verified against public CAs) or http:// (only for local testing); redirects are not followed, and a 3xx counts as a failed delivery. Each event is recorded atomically with the change that produced it: if the change is committed, the event is guaranteed to be sent. A 2xx response counts as delivered; otherwise delivery is retried with exponential backoff starting at 1 minute (at most 1 hour apart), and abandoned if still undelivered after 24 hours. Request header Temper-Signature: t=<unix seconds>,v1=<hex>, where hex = HMAC-SHA256(webhook secret, "."), the same scheme as Stripe: check the timestamp (5-minute window by default), compare in constant time, and allow for multiple v1 values. Use Temper-Event-Id to deduplicate. Covers events related to the Agent registering schedules / keep-awake from inside the VM (source: agent), and suspension for exceeding a usage limit (environment.limit_exceeded).

Parameters

ParameterInTypeDescription
Temper-Signaturerequiredheaderstring
Temper-Event-Idrequiredheaderstring

Request body application/json · WebhookEvent

FieldTypeDescription
idrequiredstring
typerequired"environment.agent_schedule_set" | "environment.agent_schedule_deleted" | "environment.agent_keep_awake" | "environment.agent_keep_awake_released" | "environment.agent_request_rejected" | "environment.limit_exceeded"

environment.<event>.

createdrequiredstring (date-time)
environment_idrequiredstring
datarequiredobject

Event details; fields vary by event. Agent-related events carry source: agent; environment.limit_exceeded is {reason}.

Responses

  • 200Any 2xx counts as delivered

Connection changes (created, revoked, refresh failed)

POSTyour webhook URL

Delivery, signing and retries are the same as for environmentEvent.

Parameters

ParameterInTypeDescription
Temper-Signaturerequiredheaderstring
Temper-Event-Idrequiredheaderstring

Request body application/json · ConnectionWebhookEvent

FieldTypeDescription
idrequiredstring
typerequired"connection.created" | "connection.revoked" | "connection.error"
createdrequiredstring (date-time)
environment_idrequiredstring

Empty string for connection.created and connection.revoked; for connection.error, the environment that triggered the refresh.

datarequiredobject

connection.created: provider, connectors, account, replaced (the id of the old connection it replaced, or null); connection.revoked: provider; connection.error: error.

Responses

  • 200Any 2xx counts as delivered

An action needs the end user's approval

POSTyour webhook URL

Delivery, signing and retries are the same as for environmentEvent. Your backend shows summary to the end user and, once it has a decision, POSTs it to decision_url with the same kind of signature (or calls decideApproval with an API key). If no decision is made before expires_at, the request counts as denied. If you have not set a webhook URL, this is not sent, and approval requests can only be decided with an API key or left to expire.

Parameters

ParameterInTypeDescription
Temper-Signaturerequiredheaderstring
Temper-Event-Idrequiredheaderstring

Request body application/json · ApprovalRequestedEvent

FieldTypeDescription
idrequiredstring
typerequired"approval.requested"
createdrequiredstring (date-time)
environment_idrequiredstring
datarequiredobject

Responses

  • 200Any 2xx counts as delivered

The Agent asks the end user to take over the browser

POSTyour webhook URL

The Agent inside the VM asks the end user to take over when it hits a sign-in or a CAPTCHA (at most once per minute per lease). Your frontend calls takeoverBrowserLease to get a viewer URL for the end user. Delivery, signing and retries are the same as for environmentEvent.

Parameters

ParameterInTypeDescription
Temper-Signaturerequiredheaderstring
Temper-Event-Idrequiredheaderstring

Request body application/json · TakeoverRequestedEvent

FieldTypeDescription
idrequiredstring
typerequired"browser.takeover_requested"
createdrequiredstring (date-time)
environment_idrequiredstring
datarequiredobject

Responses

  • 200Any 2xx counts as delivered