Skip to content

🐛 Fixing verifyWebhook to return the payloads PDFMonkey actually sends - #21

Merged
simonc merged 2 commits into
mainfrom
webhook-payloads
Oct 5, 2026
Merged

simonc merged 2 commits into
mainfrom
webhook-payloads

Conversation

@simonc

@simonc simonc commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Summary

verifyWebhook() rejected every real webhook. After the signature check passed, it required a { type, data, timestamp } envelope, but the backend sends the body as-is (DocumentGenerations::WebhookBroadcastingJob, SendQuotaNotificationsJob):

  • documents.generation.success / documents.generation.failure: { "document": <document card JSON> }
  • quota.warning: { period_start, period_end, available_documents, threshold }

The event names document.done / document.error never existed either.

Changes

  • verifyWebhook() keeps the signature and timestamp checks, then returns the parsed body as WebhookPayload (DocumentWebhookPayload | QuotaWarningWebhookPayload). The only shape check left is that the body is a JSON object.
  • DocumentWebhookPayload.document reuses DocumentCard. The event type isn't in the body, so callers check 'document' in payload and payload.document.status.
  • Removed WebhookEvent, WebhookEventType, DocumentDoneEvent(Data), DocumentErrorEvent(Data) and UnknownWebhookEvent. This is a minor bump: the types change, but the old shape never worked against the live API.
  • Updated the README example and recipes, and rewrote the test fixtures to the real shape.

Notes

Testing

  • pnpm test (212 passed), pnpm lint, tsc --noEmit and pnpm build pass.

@simonc
simonc merged commit af5932f into main Oct 5, 2026
6 checks passed
@simonc
simonc deleted the webhook-payloads branch October 5, 2026 22:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant