SteveSteve

Shelf Watcher event

Steve POSTs this to the shelf session's `webhookUrl` when an analysis completes, is blocked, fails or is cancelled, and when a review is confirmed. `X-Webhook-Id` equals the body's `id`; retries keep both and the body unchanged.

Authorization

AuthorizationRequiredBearer <token>

Steve API key, usually scoped to a company. Legacy keys and keys created by platform administrators may be unscoped; company-scoped endpoints reject unscoped keys with 403 Forbidden. Format: Authorization: Bearer aok_...

In: header

Request Body

application/jsonRequired
idRequiredstring

Event ID. Deduplicate deliveries by this value.

typeRequiredstring
Value in: "shelf.analysis.completed" | "shelf.analysis.blocked" | "shelf.analysis.failed" | "shelf.analysis.cancelled" | "shelf.review.confirmed"
occurredAtRequiredstring
Format: "date-time"
sessionRequiredobject

Header Parameters

X-Webhook-SignatureRequiredstring

sha256= followed by the lowercase hex HMAC-SHA256 of the raw request body. The HMAC key is the API key's SHA-256 digest rendered as lowercase hex.

Pattern: "^sha256=[0-9a-f]{64}$"
X-Webhook-EventRequiredstring

The event type, equal to the type carried in the body.

X-Webhook-IdRequiredstring

Event ID, unchanged across retries of the same event. Deduplicate deliveries by this value.

X-Webhook-TimestampRequiredstring

Unix seconds when this delivery attempt was sent. Changes on every retry.

Pattern: "^[0-9]+$"
User-AgentRequiredstring

Sender identifier.