SteveSteve

Batch completed

Steve POSTs this once every session in a batch has reached a final state. Retries keep the same `X-Webhook-Id` and body.

Authorization

AuthorizationRequiredBearer <token>

Steve API key, usually scoped to a company. Legacy keys and keys created by platform administrators may be unscoped; company-scoped endpoints reject unscoped keys with 403 Forbidden. Format: Authorization: Bearer aok_...

In: header

Request Body

application/jsonRequired
eventRequiredunknown
batchRefRequiredstring
countsRequiredobject
completedAtRequiredstring
Format: "date-time"

Header Parameters

X-Webhook-SignatureRequiredstring

sha256= followed by the lowercase hex HMAC-SHA256 of the raw request body. The HMAC key is the API key's SHA-256 digest rendered as lowercase hex.

Pattern: "^sha256=[0-9a-f]{64}$"
X-Webhook-EventRequiredstring

The event type, equal to the type carried in the body.

X-Webhook-IdRequiredstring

Event ID, unchanged across retries of the same event. Deduplicate deliveries by this value.

X-Webhook-TimestampRequiredstring

Unix seconds when this delivery attempt was sent. Changes on every retry.

Pattern: "^[0-9]+$"
User-AgentRequiredstring

Sender identifier.