Task Callbacks
Setup a callback to your server when a task finishes running
If you supply a callback_url
argument to your function decorator, a POST request will be made to your server whenever a task finishes running. Callbacks fire for both successful and failed tasks.
Callbacks include the Task ID in the request headers, and the task response URL-encoded in the request body.
For testing purposes, you can setup a temporary webhook URL using https://webhook.site
Registering a callback URL
Callbacks can be added onto endpoints, functions, and task queues:
Callback format
Data Payload
The callback will send the response from your function as JSON, in the data
field:
Request headers
The request headers include the following fields:
x-task-timestamp
— timestamp the task was created.x-task-signature
— signature to verify that the request was sent from beta9.x-task-status
— status of the task.x-task-id
— the task ID.
Verifying Requests
Timestamp Verification
To secure your server against replay attacks, a timestamp and signature are included in the callback request headers.
As a best-practice, it is wise to check the timestamp header of each callback request. If the timestamp is over 5s old, there is a risk that the callback was not fired from beta9.
Signature Verification
The most secure way of verifying a callback request is through signature verification.
The callback request will include a header field called x-task-signature
.
x-task-signature
is a unique signature generated by converting the request body to base64, concatenating it with the timestamp, and signing it with your API token.
The code below shows how to validate a callback signature:
Was this page helpful?