Filodos

Webhook management

Create, list, delete, and test push subscriptions programmatically. All four endpoints need an administrator sign-in. What each event carries is on the webhook events page. Part of the documentation.

POST/webhooks

Subscribes one endpoint of the administrator's organization and returns the signing secret once — store it at once. The URL must be https (http works on loopback hosts only, for local testing). Valid events: geofence.enter, geofence.exit, alarm.critical, trip.ended, report.daily. Blank names, unknown events, and bad URLs read 422.

curl -X POST https://filodos.gr/filodos-dashboard/api/scoring/webhooks \
  -H "Authorization: Bearer eyJhbGciOi…" \
  -H 'Content-Type: application/json' \
  -d '{"name": "ERP visits", "url": "https://erp.example.com/filodos-hook",
       "events": ["trip.ended", "geofence.enter", "geofence.exit"]}'

{"id": 5, "name": "ERP visits", "url": "https://erp.example.com/filodos-hook",
 "events": ["geofence.enter", "geofence.exit", "trip.ended"],
 "active": true, "created_at": "2026-10-05T08:00:00+00:00",
 "secret": "9f2c…"}

GET/webhooks

Lists the organization's subscriptions, newest first — same shape as above without the secret.

curl https://filodos.gr/filodos-dashboard/api/scoring/webhooks \
  -H "Authorization: Bearer eyJhbGciOi…"

DELETE/webhooks/{id}

Deletes one subscription of the administrator's organization, effective at once. Another org's id reads 404.

curl -X DELETE https://filodos.gr/filodos-dashboard/api/scoring/webhooks/5 \
  -H "Authorization: Bearer eyJhbGciOi…"

{"id": 5, "deleted": true}

POST/webhooks/{id}/test

Posts a signed webhook.test ping to the subscription at once and returns the receiver's HTTP status — the fastest way to prove the whole chain before real events flow. A dead receiver reads 502 with the reason.

curl -X POST https://filodos.gr/filodos-dashboard/api/scoring/webhooks/5/test \
  -H "Authorization: Bearer eyJhbGciOi…"

{"id": 5, "url": "https://erp.example.com/filodos-hook", "status": 200}

GET/webhooks/{id}/deliveries

Lists the newest delivery rows of one subscription, newest first — each row shows status (sent, pending with next_retry_at, or failed with last_error), the attempts count, and the stored envelope. Use it to find which pushes never reached the receiver.

curl "https://filodos.gr/filodos-dashboard/api/scoring/webhooks/5/deliveries?limit=20" \
  -H "Authorization: Bearer [REDACTED]…"

POST/webhooks/{id}/deliveries/{delivery_id}/replay

Re-sends one stored delivery under a new delivery id, marked "replay": true in the envelope. The attempt is immediate and lands in the deliveries list like any other send. Use it after you fix the receiver to recover failed pushes. Another org's subscription or delivery id reads 404.

curl -X POST https://filodos.gr/filodos-dashboard/api/scoring/webhooks/5/deliveries/9f3a41b2-7c0e-4d9f-8a1b-2c3d4e5f6071/replay \
  -H "Authorization: Bearer [REDACTED]…"

{"delivery_id": "c41b…", "status": "sent"}