Skip to contentSaltar al contenidoAle nan kontni anПерейти к содержимомуדלג לתוכן
EstateDraftFL

For Florida law firms

Signed webhooks: nine events as they happen — ids and states only, signed, at least once, never about a matter with a wall

firm lane · Deterministic — no model call

Current availability

ShippedConfigured and enabled: the firm's admin (or a webhooks:manage key) registers, tests, rotates and disables; deliveries run every five minutes.

Where it lives
/firms/manage/api-keys (Signed webhooks) · /api/v1/webhooks · /docs/api#webhooks
What unlocks it
a firm admin, or a key holding webhooks:manage (a whole-firm attorney key), registers an https endpoint on the public internet and chooses its events

Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.

Capabilities

  • ShippedNine events: a matter's status or stage changed, a receipt was minted, a deadline was confirmed, an item awaiting the firm opened, a transfer was addressed to the firm, a consult request arrived, an approved delivery reached its client, a source the firm's work rests on changed, a client request opened or closed.
  • ShippedEach event carries ids and states only — never a name, a document or a person's words — and is recorded only when an endpoint subscribes; nothing is recorded or delivered for a matter with a wall, at the moment it happens or the moment it is delivered.
  • ShippedEach delivery is signed by the database with the endpoint's own secret (HMAC-SHA256 over the timestamp and the body; EstateDraftFL-Signature t=…,v1=…), with its event id and type in headers; the secret is shown once at registration and at rotation, and never again.
  • ShippedDelivered at least once to an address resolved and checked public at send time (no private, loopback or metadata address; the connection uses the checked address), ten seconds at most, no redirects; a failure is retried with a growing delay up to ten attempts; 410 Gone disables the endpoint.
  • ShippedEvery attempt is logged with its status code, its duration and the class of a failure — never a response body; a signed test event (data.test: true) is delivered at once and its answer shown.

Limits

  • Ten live endpoints per firm; https only, at most 2,048 characters.
  • Revoking the key that registered an endpoint disables it; a disabled endpoint is kept as a record and never enabled again (register a new one).

What EstateDraftFL refuses

Reason codeHTTPWhat it means
invalid400The address is not https on the public internet, or an event is not one of the nine — the field is named.
forbidden403Only the firm's admin, or a key holding webhooks:manage, manages its webhooks.
not_found404That endpoint is not one of this firm's.
too_many_endpoints409A firm keeps ten live endpoints — disable one first.
already_disabled409That endpoint is disabled — register a new one.
unavailable503The change could not be made just now; nothing was changed.

Evidence

  • supabase/migrations/20261002010000_phase14_webhooks.sql
  • src/lib/platform/webhook-delivery.ts
  • src/lib/platform/webhooks.ts
  • src/app/api/cron/webhook-deliveries/route.ts
  • src/components/platform/WebhooksManager.tsx
  • src/lib/platform/platform.test.ts

Last reviewed 2026-10-02

← All surfaces