Webhooks
GET|POST /v0/webhooks · GET|PATCH|DELETE /v0/webhooks/:id
(inbox and project twins, plus /headers sub-routes).
whsec_…. Every delivery carries svix-id, svix-timestamp
and svix-signature (v1,<base64 HMAC-SHA256 of "id.timestamp.body">) —
verify with the Svix library or verifySignature() in @lupin/sdk
(HMAC hex of the raw body — parse after verifying).
Event types: email.received (+ .spam / .blocked / .unauthenticated
variants), email.sent, email.delivered, email.bounced,
email.complained, email.rejected, email.opened, domain.verified.
Payloads wrap the resource: { type: "event", event_type, event_id, message: … }.
Filter by scope with inbox_ids / project_ids at create time, or
add_inbox_ids / remove_inbox_ids (and project equivalents) on update.
Custom headers
Values are write-only: sent with each delivery, never returned.GET …/:id/headers lists names only; PATCH rotates atomically: