Skip to main content
WEBHOOK

Authorizations

Authorization
string
header
required

Authorization: Bearer . An application key (tk_live_, tk_test_) has full access, which covers every product and any product added later, or custom access, chosen when the key is created: one or more of the scopes verify:check, verify:send (includes verify:check), notifications:read, notifications:send (includes notifications:read). A call outside the key's access answers 403 insufficient_scope and names the scope it needs in the WWW-Authenticate response header. A partner key (tk_partner_) always has full access. Whatever its access, a key is a server-side secret.

Headers

tawked-timestamp
string
required

Milliseconds since the epoch, as a string; the same value as sent_at.

tawked-signature
string
required

Hex HMAC-SHA256 of "{timestamp}.{raw body}" with your webhook secret.

tawked-event
enum<string>
required

The event name, the same as event in the body.

Available options:
service.restored

Body

application/json
event
string
data
object
sent_at
string

Response

200

Any 2xx answer within 5 seconds acknowledges the delivery. Anything else, a redirect or no answer in time is retried: 5 attempts in all, the first at once and the next after 1 min, 5 min, 30 min, 2 h.

Last modified on October 6, 2026