Available events
A connection only sees the events its scopes allow, and only for resources that belong to its agent. Phone and social events appear only when those features are enabled for your organization.
events/list returns the exact list with input and payload schemas.
Payload
Every delivery is a POST with a JSON body:cursor is a position you can store: every event at or before it has been delivered. Pass it to events/subscribe after an interruption to receive what you missed.
Delivery and signing
- Before the first delivery to a callback URL, the server sends a signed
{"type": "verification", "challenge": "…"}request. The endpoint must answer2xxwith{"challenge": "…"}echoing the value. - Requests are signed with Standard Webhooks using the
whsec_secret the client supplied. The headers arewebhook-id(the event ID),webhook-timestamp,webhook-signatureandX-MCP-Subscription-Id. After a secret rotation, deliveries carry both signatures for a day. - A
2xxresponse acknowledges the event. Other responses are retried with increasing delays, six attempts in total.410 Goneremoves the subscription, and413is not retried. - After 50 failed attempts in a row, delivery pauses until the client subscribes again.
- Callback URLs must use HTTPS and resolve to a public address. Redirects are not followed.
Subscriptions
Subscribing again with the same connection, callback URL, event and arguments updates the existing subscription instead of creating another.
Revoking the connection on the agent’s Tokens tab ends all of its subscriptions. Access is checked again before every delivery, so deliveries also stop when you remove a scope, delete the inbox or phone number, or remove the agent’s access to a social account.