> ## Documentation Index
> Fetch the complete documentation index at: https://docs.frayme.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Webhooks and delivery history

> Where Frayme posts decisions and callbacks, how to keep and rotate signing secrets, and how to inspect and resend deliveries.

export const Clip = ({id, caption}) => <Frame caption={caption}>
    <video controls muted playsInline preload="metadata" className="w-full aspect-video rounded-xl" poster={`/videos/guides/${id}.poster.png`} src={`/videos/guides/${id}.mp4`} />
  </Frame>;

export const Shot = ({id, alt, caption}) => <Frame caption={caption}>
    <img className="block dark:hidden rounded-lg" src={`/images/guides/${id}.light.png`} alt={alt} loading="lazy" decoding="async" />
    <img className="hidden dark:block rounded-lg" src={`/images/guides/${id}.dark.png`} alt={alt} loading="lazy" decoding="async" />
  </Frame>;

## How Frayme reaches you

Frayme posts JSON to **webhook configs** you create: `case.decided`, `case.pending_review`, `case.decision_overridden`, `case.rfi_requested` and node callbacks. Every post carries `X-Frayme-Signature`, an HMAC-SHA256 of the raw body with the config's signing secret. Deliveries retry with backoff and are at-least-once; dedupe on `webhookId`, except `case.rfi_requested`, which you dedupe on its `rfi_id`.

<Shot id="engineer/wh-01-configs" alt="Webhooks card" caption="Named endpoints with their secret ids." />

<Clip id="engineer/webhook-add-and-rotate" caption="Add an endpoint, keep the secret, rotate it, open Delivery History." />

## Add a webhook config

<Steps>
  <Step title="Click Add webhook config">
    **Name** is how flows reference it (leave blank to create the tenant's `default`). **URL** is your HTTPS endpoint.

    <Shot id="engineer/wh-02-add-config" alt="Add webhook config dialog" caption="Name and URL." />
  </Step>

  <Step title="Keep the signing secret">
    **Signing secret · name** is shown once. Store it where your endpoint verifies signatures.

    <Shot id="engineer/wh-03-secret-reveal" alt="Signing secret dialog" caption="Shown once." />
  </Step>
</Steps>

## Change the URL

Edit the URL in the row and click **Save**.

## Rotate the secret

**Rotate secret** issues a new secret and shows it once. Deliveries carry `X-Frayme-Secret-ID` so your endpoint can keep both secrets while you switch.

<Shot id="engineer/wh-04-rotate-reveal" alt="Rotated secret dialog" caption="The new secret." />

## Delete

**Delete webhook config?** removes the endpoint. Flows that reference it fail validation until they point elsewhere.

<Shot id="engineer/wh-05-delete-confirm" alt="Delete webhook config dialog" caption="Flows referencing the config will fail validation." />

## Route events to a config

There is no event-type subscription. A config receives what is routed to it: a flow's **Result webhook** (workflow config in the builder), a node's **Webhook notify** or **Async callback mode**, and the **Communication Webhook** in **Settings → Communication** for information requests.

## Delivery History

**Delivery History** opens [`/webhook-history`](https://console.us.frayme.io/webhook-history): recent deliveries with case id, source, config, status (**Delivered**, **Failed**, **Retrying**, **Pending**), attempts and timestamps, refreshed every ten seconds. Filter by **Case ID**, event type and page size.

<Shot id="engineer/wh-06-history-list" alt="Webhook Delivery History" caption="Recent deliveries." />

<Shot id="engineer/wh-07-history-filters" alt="Delivery filters" caption="Filter by event type." />

## Inspect and resend

Click a row for the payload (with **Copy**) and the per-attempt history: status code, error and duration. **Resend webhook** queues another attempt; the toast reads **Retry queued**.

<Shot id="engineer/wh-08-history-detail" alt="Delivery detail sheet" caption="Payload and attempts." />

<Shot id="engineer/wh-09-resend-toast" alt="Retry queued toast" caption="Resend." />

## Verify signatures

See [Webhooks](/api-reference/webhooks) in the API reference for the headers, the verification snippet and the retry schedule.
