From ee14073ab9c2d3b1748b4fbe33d0b628d8e0c83f Mon Sep 17 00:00:00 2001 From: Alex Luong Date: Mon, 21 Sep 2026 22:49:57 +0700 Subject: [PATCH] docs(api): add v1.4.0 webhook options to ManagedConfig Co-Authored-By: Claude Opus 5 (1M context) --- docs/apis/openapi.yaml | 61 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 61 insertions(+) diff --git a/docs/apis/openapi.yaml b/docs/apis/openapi.yaml index 2909801a9..e7200cfe6 100644 --- a/docs/apis/openapi.yaml +++ b/docs/apis/openapi.yaml @@ -3119,6 +3119,49 @@ components: type: string DESTINATIONS_INCLUDE_MILLISECOND_TIMESTAMP: type: string + DESTINATIONS_WEBHOOK_COMPAT_HEADERS: + type: string + description: >- + Additional headers sent with the compat signature, as comma-separated + "name=template" pairs. Available variables: {{.EventID}}, {{.Topic}}, + {{.Timestamp}}. Use "\," for a literal comma in a template. + DESTINATIONS_WEBHOOK_COMPAT_SIGNATURE_ALGORITHM: + type: string + description: >- + Algorithm for the compat signature. Defaults to "hmac-sha256". + DESTINATIONS_WEBHOOK_COMPAT_SIGNATURE_CONTENT_TEMPLATE: + type: string + description: >- + Go template for the content signed by the compat signature. Same + variables as DESTINATIONS_WEBHOOK_SIGNATURE_CONTENT_TEMPLATE. + Defaults to "{{.Body}}". + DESTINATIONS_WEBHOOK_COMPAT_SIGNATURE_ENCODING: + type: string + description: >- + Encoding for the compat signature ("hex" or "base64"). Defaults to + "hex". + DESTINATIONS_WEBHOOK_COMPAT_SIGNATURE_HEADER_NAME: + type: string + description: >- + Complete name of the compat signature header. Setting it sends a + second signature, in a previous scheme, alongside the primary one. + DESTINATIONS_WEBHOOK_COMPAT_SIGNATURE_HEADER_TEMPLATE: + type: string + description: >- + Go template for the value of the compat signature header. Same + variables as DESTINATIONS_WEBHOOK_SIGNATURE_HEADER_TEMPLATE. + Defaults to "v0={{.Signatures | join ","}}". + DESTINATIONS_WEBHOOK_COMPAT_SIGNATURE_SECRET_ENCODING: + type: string + description: >- + How the compat signature derives its HMAC key from the destination + secret: "raw", "base64" or "hex". Defaults to "raw". A destination + whose secret can't be decoded doesn't receive the compat signature. + DESTINATIONS_WEBHOOK_COMPAT_SIGNATURE_SECRET_PREFIX: + type: string + description: >- + Prefix stripped from the destination secret before decoding for the + compat signature (e.g., "whsec_"). DESTINATIONS_WEBHOOK_EVENT_ID_HEADER_NAME: type: string description: >- @@ -3145,8 +3188,26 @@ components: empty string disables the header. Only applies to "default" mode. DESTINATIONS_WEBHOOK_SIGNATURE_HEADER_TEMPLATE: type: string + DESTINATIONS_WEBHOOK_SIGNATURE_SECRET_ENCODING: + type: string + description: >- + How the signature derives its HMAC key from the destination secret: + "raw" uses the secret as-is, "base64" and "hex" decode it. Defaults + to "raw". DESTINATIONS_WEBHOOK_SIGNING_SECRET_TEMPLATE must generate + secrets this encoding can decode. Only applies to "default" mode. + DESTINATIONS_WEBHOOK_SIGNATURE_SECRET_PREFIX: + type: string + description: >- + Prefix stripped from the destination secret before decoding (e.g., + "whsec_"). Ignored when DESTINATIONS_WEBHOOK_SIGNATURE_SECRET_ENCODING + is "raw". Only applies to "default" mode. DESTINATIONS_WEBHOOK_SIGNING_SECRET_TEMPLATE: type: string + DESTINATIONS_WEBHOOK_TIMESTAMP_FORMAT: + type: string + description: >- + Format of the timestamp header: "rfc3339" or "unix". Defaults to + "rfc3339". Only applies to "default" mode. DESTINATIONS_WEBHOOK_TIMESTAMP_HEADER_NAME: type: string description: >-