Only the Workspace Owner can configure or update the account webhook URL.
Configure an account webhook
1
Open Developer settings
In Lumin, go to Settings → Developer settings → API Key tab.
2
Enter your webhook URL
In the Account callback section, enter your endpoint URL. The URL must
use HTTPS.
3
Save
Click Save. Lumin will begin delivering events to your endpoint
immediately.
Events received
Your account webhook receives all supported event types from across your workspace. There is no filtering — you receive every event triggered by any user or API key in the workspace.Verify webhook signatures
Every request Lumin sends includes the following headers:User-Agent: AlwaysLumin Sign APIX-Signature: An HMAC-SHA256 hex digest of the request body, signed with your Primary API key
1
Read the header
Extract the
X-Signature value from the incoming request headers.2
Compute the expected signature
Compute HMAC-SHA256 of the raw request body using your Primary API key as
the secret.
3
Compare
Compare your computed value to the
X-Signature header. Use a constant-time
comparison to avoid timing attacks.4
Reject mismatches
If the values do not match, reject the request with a non-200 status.
Respond to events
Your endpoint must return HTTP200 OK within 30 seconds of receiving a request. No response body is required.
Error handling and retries
If your endpoint does not return200 OK, Lumin retries the delivery. The following conditions trigger a retry:
- HTTP
4xxor5xxresponse - No response within 30 seconds (timeout)
- Connection failure