POST requests that name the accounts that changed, and nothing else.
Webhooks are available to applications created as A website or a server. Drime has to reach a server of yours, and a desktop, mobile or script application has none.
1. Set the endpoint
In the developer console, open your application, then Webhooks. Paste anhttps:// address and click Verify and save.
Drime calls it straight away with a challenge:
200 with the challenge as the whole body:
- start with
https://; - use a hostname, not an IP address;
- resolve to public addresses only, which Drime checks again before every delivery, not only when you save;
- carry no credentials and no
#fragment; - be 500 characters at most.
2. Copy the signing secret
Once the endpoint is saved, the Webhooks tab shows its signing secret, starting withwhsec_. Keep it on your server, like a password: it is what proves a notification comes from Drime.
To get a new one, remove the endpoint and save it again. The old secret stops working at once.
3. Receive notifications
user.id that GET /users/me returned when that user authorized you. For each account, ask the API what is new, with the token you hold for that user.
Answer 200 within 10 seconds, then do the work in a queue. Drime does not wait and does not resend: whatever you miss will show up the next time you look, because a notification never carries the data.
4. Check the signature
X-Drime-Signature is the hexadecimal HMAC-SHA256 of the raw request body, keyed with your signing secret. Compute it on the exact bytes you received, before parsing anything, and compare in constant time. Your endpoint is public: anyone can send it a request.
What sends a notification
- Something is created in the account: an upload, a new folder or document, a copy.
- Something is deleted: moved to the trash, or deleted for good.
Frequency and limits
Drime only notifies an application about accounts that have connected it, and stops as soon as the user disconnects it.
Checklist
- The challenge handler answers with the challenge only, as
text/plain. - The signature is checked on the raw body, in constant time, with the signing secret.
200goes out before the work starts.- The work can run twice for the same account without harm, and does not depend on every notification arriving.
- The endpoint resolves to a public address and is not behind a redirect.