Shelf Watcher event
Steve POSTs this to the shelf session's `webhookUrl` when an analysis completes, is blocked, fails or is cancelled, and when a review is confirmed. `X-Webhook-Id` equals the body's `id`; retries keep both and the body unchanged.
Authorization
AuthorizationRequiredBearer <token>Steve API key, usually scoped to a company. Legacy keys and keys created by platform administrators may be unscoped; company-scoped endpoints reject unscoped keys with 403 Forbidden. Format: Authorization: Bearer aok_...
In: header
Request Body
application/jsonRequiredidRequiredstringEvent ID. Deduplicate deliveries by this value.
typeRequiredstring"shelf.analysis.completed" | "shelf.analysis.blocked" | "shelf.analysis.failed" | "shelf.analysis.cancelled" | "shelf.review.confirmed"occurredAtRequiredstring"date-time"sessionRequiredobjectHeader Parameters
X-Webhook-SignatureRequiredstringsha256= followed by the lowercase hex HMAC-SHA256 of the raw request body. The HMAC key is the API key's SHA-256 digest rendered as lowercase hex.
"^sha256=[0-9a-f]{64}$"X-Webhook-EventRequiredstringThe event type, equal to the type carried in the body.
X-Webhook-IdRequiredstringEvent ID, unchanged across retries of the same event. Deduplicate deliveries by this value.
X-Webhook-TimestampRequiredstringUnix seconds when this delivery attempt was sent. Changes on every retry.
"^[0-9]+$"User-AgentRequiredstringSender identifier.