Skip to main content
Polling adds latency and burns rate-limit headroom. Webhooks let AcreLens push completed reports to your endpoint the moment they finish.

Configure your endpoint

You can set webhook URLs at two levels:
  • Per-customer default — set in the dashboard under Manage → Webhooks. Applies to every report unless overridden.
  • Per-request override — pass webhook_url in the request body of POST /v1/analyze or POST /v1/batch. Useful for routing different report types to different services.

Events

Headers

Every delivery includes these:

Payload examples

report.completed

Mirrors the GET /v1/reports/{id} response when status is completed — same fields, same shape:
See the endpoint reference for the full response schema with field descriptions.

report.failed

batch.completed

Signature verification

The X-AcreLens-Signature header has the form:
To verify a delivery:
  1. Pull t and v1 out of the header.
  2. Reject if t is more than 5 minutes old (replay protection).
  3. Compute HMAC-SHA256(secret, "{t}.{raw_request_body}") and compare to v1 using a constant-time comparison.
Use the raw request body bytes — don’t re-serialize the parsed JSON, or whitespace differences will break the signature.

Node.js

Python

Webhook secret

Your webhook secret lives in the dashboard under Manage → Webhooks. It’s:
  • Per-customer (one secret used for all your webhook deliveries)
  • Rotatable (creates a new secret; old one immediately stops working)
  • Treated as sensitive — store it like an API key, in env vars or a secret manager

Retry schedule

If your endpoint returns a non-2xx status, doesn’t respond within 30 seconds, or has a network error, AcreLens retries up to 7 times total (the initial attempt plus 6 retries): Retried on: 5xx, 408, 429, network errors, timeouts. Not retried on: 2xx, 3xx, all other 4xx (including 410 Gone, which signals “stop trying”). After all retries are exhausted, the delivery is marked failed and visible in the dashboard. There’s no automatic resurrection — you’d need to refetch the report manually if you want the data.

Idempotency in your handler

AcreLens may deliver the same event more than once if your endpoint is slow to respond. Use the X-AcreLens-Delivery header (unique per delivery attempt) to dedupe — but better, key off report_id since that’s stable across retries:

Local development

Use ngrok, cloudflared, or tailscale funnel to expose your local server. Drop the public URL into your dashboard’s webhook config — there’s no separate sandbox environment to wire up.

Failures don’t affect quota

Webhook delivery failures don’t consume API quota or cost you anything beyond the original report charge. Reports are still available via GET /v1/reports/{id} if your webhook endpoint never receives them.