Repository navigation
Conversation
The guide and jobs docs said what job create returns but not how a sender uses signing_secret: the X-OpenProse-Delivery header and HMAC-SHA256 over deliveryId + "\n" + rawBody. Add both with an openssl + curl recipe and the response codes, and correct endpointUrl to endpoint_url in the guide and schemas README. Regenerate the pinned guide cases. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 7, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two doc fixes found while an agent set up a new webhook job using only this repo's docs:
job createreturnssigning_secretandendpoint_url, but neither the guide nordocs/service/jobs.mdsaid how a sender uses them. The requiredX-OpenProse-Deliveryheader and the HMAC-SHA256 overdeliveryId + "\n" + rawBodywere only in the service's web setup text, so a sender working from this repo got400/401.guide.v1.mdsaidresult.endpointUrl, andcli/shared/schemas/README.mdsaidendpointUrlinjob show. The result, schema andjobs.mdall useendpoint_url.Changes
cli/shared/service/guide.v1.md:endpointUrl→endpoint_url.openssl+curlsigning recipe, and what202/test_only/400/401/413mean.docs/service/jobs.md: new "Sending events to a webhook" section with:last_event_atrecords live deliveries only;liveneeds a contract;cli/shared/schemas/README.md:endpointUrl→endpoint_url.cli/conformance/cases/service/framework/service-guide-{human,json,jsonl}.json: regenerated withpython3 cli/ci/render_service_help.py --write.No code changes. The guide stays ASCII and free of internal nouns.
Evidence
Hosted service. Checked with a
dev-endpointbuild, using a test-mode webhook with no program, so no runs and no spend:openssl+curlrecipe202 {"accepted":true,"duplicate":false,"test_only":true}400400 {"error":"Webhook payload must be valid JSON"}413 {"error":"Webhook payload is too large"}401; shows injob deliveriesasrejected/invalid_signature202, recorded againjob updatetolivewithout a contractSERVICE_REQUEST_REJECTED("Runs stay disabled. Connect a contract to this webhook first.")Not observed live. The live-mode
duplicate:trueand409rows need an attached contract, which means paid runs. They match the service's webhook handler and its own sender instructions, and the table marks them "Live mode".Local gates. Run on macOS with Python 3.10.21 and Rust from
rust-toolchain.toml. These nine pass:shared-contractsservice-helppublic-surface-filesdifferential-conformance: 64 cases × 2 productsservice-operations-corpusservice-operations-rust-buildservice-operations-rust: 1089 casesservice-operations-bun-buildservice-operations-bun: 1089 casesAlso passing:
render_service_help.py --checktest_user_text.pytest_service_contract.pyNot run. The full
run_local.py. Twobun-testscases (dev-endpoint.test.ts,build-identity.test.ts) fail identically on unmodifiedmain@8e2a258on this machine. It has Bun 1.4.2 instead of the pinned 1.3.5, and this PR touches no Bun code.🤖 Generated with Claude Code