Receive a provider delivery receipt for a routed platform child.
POST/v1/webhooks/:provider/:token
The per-child callback URL is
https://api.nervly.io/v1/webhooks/{provider}/{token} where the token is
the immutable platform_provider_accounts.id. The callback is verified
against that child's platform-scoped signing secret (never the
deployment-wide platform secret, never another workspace's), and where the
payload echoes a provider-native child id it is cross-checked against the
routed account. An unknown token, a token for another provider, a non-ready
account, a native-id mismatch or a missing/undecryptable child secret is
refused fail-closed, alerted and quarantined — never adopted and never
attributed to the platform account.
Request
Responses
- 200
- 401
- 403
- 404
- 500
- 503
Receipt accepted and published to telemetry
Child secret is missing or the signature did not verify
The callback's native child id does not match the routed account
Unknown token, wrong provider, or a non-ready child
Protobuf or JSON encoding failure
The child account store is unreachable or the broker is unavailable; the provider should retry