Register a ServeManager webhook and verify inbound payload authenticity using the HMAC-SHA256 signature header

domain: servemanager.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Authenticate via HTTP Basic Auth with the API key
  2. POST /api/webhooks with a name, target_url, and an array of event types (e.g. 'jobs:created', 'jobs:updated', 'invoices:created')
  3. Store the returned client_reference_key so the same webhook can later be updated idempotently
  4. On the receiving endpoint, read the X-SM-HMAC-SHA256 header on every inbound POST and compute an HMAC-SHA256 digest of the raw request body using your webhook secret key before trusting the payload
  5. Use PUT /api/webhooks with client_reference_key and update_if_exists to modify an existing subscription's events or target_url instead of creating a duplicate
  6. DELETE /api/webhooks/:id to remove a subscription that is no longer needed

Known gotchas

Related routes

Register a Finch webhook endpoint and verify signatures with HMAC-SHA256
hr-payroll · 5 steps · unrated
Subscribe to Lodgify webhooks and verify inbound event payloads using HMAC signature validation
docs.lodgify.com · 5 steps · unrated
Verify AfterShip Tracking API webhook payloads using the HMAC signature header
aftership.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans