Integrations
Webhook operations
Manage signed AffixIO delivery streams, receiver health, verification steps, and evidence exports from one private Hub console.
Point AffixIO at an HTTPS receiver on your infrastructure. After you add the endpoint, the signing secret is displayed once. Store it before you leave the page.
| Label | URL | Events | Last delivery | Status | Actions |
|---|---|---|---|---|---|
| Loading endpoints... | |||||
Read the headers
Each POST carries X-Affix-Event, X-Affix-Timestamp, X-Affix-Delivery-Id and X-Affix-Signature.
Recompute the MAC
The signature is hmac-sha256=HEX of HMAC-SHA256(secret, "{timestamp}.{raw_body}"). Compare in constant time.
Reject stale timestamps
Drop deliveries where the timestamp is more than five minutes from now to block replays. Deliveries retry up to three times.
Choose a time window and format. The file streams from your Hub session, so no API key is required while you are signed in.
Endpoints
GET /api/export/siem and GET /api/export/evidence on api.affix-io.com. Query params: since, until, format, limit.
Event types
Prove, verify, gate, attest, Merkle leaf, spend, revoke, key.revoked, webhook.delivery, plus raw API request rows where classified.
Retention
Events come from the live file-backed logs on the API host. Older rows roll off when each log hits its configured ceiling.