Create webhook
tribeunal_create_webhookRegister an https URL to receive signed POST events for cases you own. Get a one-time signing secret for HMAC verification, with retries and deduplication support.
Instructions
Register a URL that Tribeunal will POST your cases' events to. Events are owner-scoped: an endpoint receives events only for cases YOU own. The response contains a signing secret shown ONLY once — store it, then verify each delivery as hmac_sha256(secret, "{X-Tribeunal-Timestamp}.{raw body}") against the hex in X-Tribeunal-Signature (format "v1="). Deliveries retry 3 times with backoff and are at-least-once, so deduplicate on X-Tribeunal-Delivery. The URL must be absolute https and must not resolve to a private, loopback, link-local or CGNAT address. An 11th endpoint answers 409 endpoint_limit (cap: 10 per account). Change events or pause delivery with tribeunal_update_webhook; the URL and secret cannot be changed — delete with tribeunal_delete_webhook and re-create instead. Returns {uuid, url, events, active, secret} — secret appears here and nowhere else.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | Absolute https URL to receive the signed POST deliveries; rejected (400 invalid_url / url_not_allowed) if it isn't https, carries embedded credentials, or resolves to a private, loopback, link-local, or CGNAT address. | |
| events | Yes | One or more of case.opened, case.closed, vote.cast, vote.revoked, comment.created, evidence.marked, evidence.unmarked, jury.joined, ping; an unknown name answers 400 invalid_events. 'ping' fires only when the endpoint is pinged from the web dashboard or API — no MCP tool sends it. |