Skip to main content
WEBHOOK

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

X-Orb-Signature
string
required

v1= followed by the hex HMAC-SHA256 of v1:{X-Orb-Timestamp}:{raw request body}, keyed by the endpoint's webhook secret. The header may carry several space-separated signatures during a secret rotation; a receiver accepts the delivery when any v1 signature matches. Compare in constant time, and sign the bytes as received rather than a re-serialized body.

X-Orb-Timestamp
string<date-time>
required

When the delivery was signed, ISO 8601 to milliseconds. It is part of the signed message, so a receiver must reject timestamps outside its tolerance to stop replays.

Body

application/json

Issued when a license allocation is reset.

id
string
required

The ID of this webhook event.

created_at
string<date-time>
required

The time at which this event was created, to the second.

type
enum<string>
required

The event this payload describes.

Available options:
subscription.license_allocation_reset
subscription
SubscriptionWebhookSimple · object
required

A lightweight subscription representation for webhook payloads.

This avoids the expensive to_subscription_params() call required for full serialization.

properties
LicenseAllocationResetWebhookEventProperties · object
required

Fires at the start of a billing period when license allocations are replenished. Allocations sharing a billing period are batched into one message.

Response

2XX

Any 2xx acknowledges receipt.