Skip to main content

Overview

Avero sends a POST request to your endpoint URL each time a subscribed event occurs. The request body is a JSON object; the event field identifies the type.

Registering a webhook

  1. Go to Settings → Developers → Webhooks in the Avero desktop app.
  2. Click Add endpoint, enter your URL, and select the events you want.
  3. Save — Avero stores the endpoint and generates a signing secret.

Events

Payload shape

The data object is event-specific. For call.ended it includes call_id, phone_e164, duration_seconds, and technical_result.

Verifying the signature

Every delivery includes an X-Payfair-Signature header containing an HMAC-SHA256 digest of the raw request body, prefixed with sha256=. Always verify the signature before processing the payload. This prevents spoofed requests.
Use the raw request body (before any JSON parsing) for HMAC computation. Parsing and re-serialising the JSON can change byte order and invalidate the signature.

Retry schedule

If your endpoint returns a non-2xx status or times out, Avero retries the delivery on this schedule: After 5 failed retries the delivery is marked failed. You can manually replay individual deliveries from Settings → Developers → Webhook delivery log.

Best practices

  • Respond quickly. Return 200 OK as soon as you receive the request, then process asynchronously. Avero times out after 10 seconds.
  • Make handlers idempotent. The same event can be delivered more than once; use id to deduplicate.
  • Check event before acting. Subscribe only to the events you need; ignore unknown events gracefully.