Endpoint requirements
Your callback URL must:- Accept POST over HTTPS with TLS 1.2 or higher (Suki does not send webhooks to HTTP URLs)
- Be publicly reachable (no localhost or private IPs in production)
- Respond with HTTP 200 (โOKโ) within 30 seconds
Verify the request signature
Suki signs each notification. Verify before you parse JSON.
Pseudocode
Fix
1
Confirm the Registered HTTPS URL
Match the path Suki stored on your partner record. Confirm the endpoint is publicly reachable over HTTPS with TLS 1.2 or higher.
2
Verify HMAC on the Raw Body
Compute HMAC-SHA-256 over
generated-at + : + raw body with your partner secret. Compare to X-API-Key with a constant-time compare. See Signature verification.3
Return 200 Quickly
After a valid signature, return HTTP 200 (โOKโ) so Suki treats the notification as delivered. Do follow-up API or database work after you acknowledge.
4
Log Rejected Requests
Log missing headers, signature mismatches, and non-200 responses. A handler that returns 4xx/5xx or exceeds 30 seconds can look like โnothing arrivedโ in your product logs even though Suki retried.
5
Trigger a Known Session Event
Complete an Ambient or Form filling session that should emit a webhook. Dictation workflows do not send completion webhooks.
Return 200 after you receive and validate the webhook. That tells Suki the notification was delivered.