Skip to main content
If you have integrated Dropbox webhooks, this is the same design: a challenge when you set the endpoint, then signed POST requests that name the accounts that changed, and nothing else. Webhooks are available to applications created as A website or a server. Drime has to reach a server of yours, and a desktop, mobile or script application has none.

1. Set the endpoint

In the developer console, open your application, then Webhooks. Paste an https:// address and click Verify and save. Drime calls it straight away with a challenge:
Answer 200 with the challenge as the whole body:
You have 10 seconds, and redirects are not followed. Nothing is saved until the challenge comes back, and nothing is ever sent to an endpoint that has not answered one. That is what stops someone from typing your address into their own application. The address must:
  • start with https://;
  • use a hostname, not an IP address;
  • resolve to public addresses only, which Drime checks again before every delivery, not only when you save;
  • carry no credentials and no #fragment;
  • be 500 characters at most.

2. Copy the signing secret

Once the endpoint is saved, the Webhooks tab shows its signing secret, starting with whsec_. Keep it on your server, like a password: it is what proves a notification comes from Drime. To get a new one, remove the endpoint and save it again. The old secret stops working at once.

3. Receive notifications

The body names who changed, never what. Each entry is a Drime account id, as a string: the user.id that GET /users/me returned when that user authorized you. For each account, ask the API what is new, with the token you hold for that user. Answer 200 within 10 seconds, then do the work in a queue. Drime does not wait and does not resend: whatever you miss will show up the next time you look, because a notification never carries the data.

4. Check the signature

X-Drime-Signature is the hexadecimal HMAC-SHA256 of the raw request body, keyed with your signing secret. Compute it on the exact bytes you received, before parsing anything, and compare in constant time. Your endpoint is public: anyone can send it a request.
To test your code: with the secret whsec_example, the body {"list_folder":{"accounts":["1042","2099"]}} signs to 285215da10359586d6d7380abad6e81e6979a32da3f54b0a37a1910c7c789826.

What sends a notification

  • Something is created in the account: an upload, a new folder or document, a copy.
  • Something is deleted: moved to the trash, or deleted for good.
Renames, moves, edits and restores do not send one. Neither does anything in the Vault, which is end-to-end encrypted. A change notifies every application that the owner of the changed item has connected, as long as its endpoint works. The notification names the account, not a folder or a workspace: an application that works in its own folder can be told about a change made elsewhere in the Drive. List your folder to see whether anything changed in it.

Frequency and limits

Drime only notifies an application about accounts that have connected it, and stops as soon as the user disconnects it.

Checklist

  • The challenge handler answers with the challenge only, as text/plain.
  • The signature is checked on the raw body, in constant time, with the signing secret.
  • 200 goes out before the work starts.
  • The work can run twice for the same account without harm, and does not depend on every notification arriving.
  • The endpoint resolves to a public address and is not behind a redirect.