> ## Documentation Index
> Fetch the complete documentation index at: https://milford.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Send a signed webhook

> Runs the flow of a webhook channel. It does not use the bearer token. Sign the request instead:
`x-milford-signature` is `sha256=` plus the hex HMAC-SHA256 of `<x-milford-timestamp>.<raw body>` with the
channel secret. Timestamps more than five minutes from the server clock are rejected.




## OpenAPI

````yaml /openapi.yaml post /hooks/{id}
openapi: 3.1.0
info:
  title: Milford HTTP API
  version: 0.0.1
  description: >
    Run flows, list them, and receive signed webhooks. The server is stateless
    and has no database.

    Generate a client for your language from this file with any OpenAPI
    generator.
servers:
  - url: http://localhost:8080
security:
  - bearer: []
paths:
  /hooks/{id}:
    post:
      summary: Send a signed webhook
      description: >
        Runs the flow of a webhook channel. It does not use the bearer token.
        Sign the request instead:

        `x-milford-signature` is `sha256=` plus the hex HMAC-SHA256 of
        `<x-milford-timestamp>.<raw body>` with the

        channel secret. Timestamps more than five minutes from the server clock
        are rejected.
      operationId: webhook
      parameters:
        - name: id
          in: path
          required: true
          description: Channel id.
          schema:
            type: string
        - name: x-milford-timestamp
          in: header
          required: true
          description: Current Unix time in seconds.
          schema:
            type: string
        - name: x-milford-signature
          in: header
          required: true
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              description: The whole body becomes the flow input.
              additionalProperties: true
      responses:
        '200':
          description: The flow ran.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookResult'
        '400':
          description: The body is not a JSON object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Invalid or stale signature.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Unknown webhook.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '413':
          $ref: '#/components/responses/TooLarge'
      security: []
components:
  schemas:
    WebhookResult:
      type: object
      required:
        - ok
        - runId
      properties:
        ok:
          type: boolean
        runId:
          type: string
        output:
          type: string
        data: {}
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
  responses:
    TooLarge:
      description: The body is larger than `server.maxBodyBytes`.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: One of `server.auth.tokens`. With no tokens configured the API is open.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.