Webhooks
HMAC-signed event delivery. Subscribe to events and receive signed POST requests.
Events
run.completedrun.failedcertificate.signedverdict.submitted
Setup
POST /api/v1/webhooks
{ "url": "https://your-app.com/hook", "events": ["certificate.signed"] }
Signature: EvalDesk-Signature: t=<ts>,v1=<hmac>. Verify with the signing secret (returned once at creation).