Skip to main content
POST
Twitter webhook test & signed delivery check
Free. This endpoint does not consume credits.
These snippets build a small deployment-check record. Store accepted, status_code, and error with the webhook ID. Do not print the full test response.

Path parameters

string
required
The webhook ID to test.

Headers

string
required
Your API key. This endpoint also accepts session cookie authentication.

What happens

Xquik sends a webhook.test event to your endpoint, HMAC-signed with the webhook’s secret:
Payload delivered to your endpoint
The signed request includes the X-Xquik-Signature, X-Xquik-Timestamp, and X-Xquik-Nonce headers. Verify the signature against the raw request body before parsing JSON. Reject stale timestamps and reused nonces. Production monitor deliveries need the same checks. You can test active, paused, or needs-attention webhooks. This endpoint reports whether the receiver accepted the signed test request. It does not change isActive, deliveryStatus, or consecutiveFailures. Xquik keeps retrying an active webhook. After a fix, call Resume Webhook. It runs the same test, then starts sending waiting and rejected deliveries at once. It also reactivates a paused webhook. The test endpoint does not return or rotate the signing secret. Keep using the secret returned by Create Webhook for signature verification. Keep raw request bodies, raw signatures, and full headers out of deployment logs. webhook.test payloads include eventType, data, and timestamp. They do not include deliveryId or streamEventId. Use them for reachability and signature checks. They cannot test receiver idempotency.

Response

200 OK (success)

boolean
true when your endpoint responded with a 2xx status code.
number
The HTTP status code returned by your endpoint.

200 OK (delivery failed)

boolean
false when your endpoint returned a non-2xx status or was unreachable.
number
The HTTP status code returned by your endpoint, or 0 if unreachable.
string
Error description (for example "HTTP 500" or a network error message).

400 Invalid request

The provided webhook ID is not a valid format.

401 Unauthenticated

Missing or invalid API key or session cookie.

404 Not found

No webhook exists with this ID, or it belongs to a different account.

429 Rate limited

Too many requests. Wait for the Retry-After header before retrying.

Test result handoff

Use this endpoint before routing production monitor events to a new receiver or after changing webhook code, secrets, firewall rules, or queue routing.

Receiver accepted

Treat success: true and a 2xx statusCode as proof that the receiver accepted the signed webhook.test request.

Receiver rejected

Treat success: false with a non-2xx statusCode as a receiver error. Fix the endpoint before waiting for the next production monitor event.

Endpoint unreachable

Treat statusCode: 0 as a network or reachability failure. Check DNS, TLS, firewall rules, and the public HTTPS URL.

Error string

Store error with your deployment logs so support, queue, or incident workers can see the latest test failure reason.

Paused or needs attention

Xquik still sends tests to paused and needs-attention webhooks. A passing test proves reachability only. Use Resume Webhook to reactivate a paused webhook. It also starts sending waiting deliveries at once.

Signature path

Validate X-Xquik-Signature, X-Xquik-Timestamp, and X-Xquik-Nonce on the raw request body before accepting test or production events.

Test payload

webhook.test payloads include eventType, data, and timestamp. They do not include deliveryId or streamEventId.

Production triage

After the receiver accepts this signed test, use List Deliveries to debug real monitor events. Delivery rows contain id, streamEventId, status, attempts, lastStatusCode, lastError, createdAt, and deliveredAt.

Event join

For failed production deliveries, use delivery streamEventId as the {id} for Get Event. Store the event monitorId, monitorType, type, occurredAt, and data with the receiver incident.
This endpoint accepts 2 auth methods. Send an API key in the x-api-key header or a session cookie from the dashboard.Related. List Webhooks · Resume Webhook · List Deliveries · Get Event · Webhook Verification