Testing your integration
There is no sandbox organization yet — test against your own organization with a narrow key, then widen it. Part of the documentation.
Test the reads
- Create a key with exactly the scopes your feed needs, for example
devices:readandtrips:readfor mileage. - Read the fleet, then one vehicle's trips:
curl https://filodos.gr/filodos-dashboard/api/scoring/devices \ -H "Authorization: Bearer filodos_…" curl 'https://filodos.gr/filodos-dashboard/api/scoring/trips?device_id=43' \ -H "Authorization: Bearer filodos_…" - Confirm a call outside the scopes reads
403— that proves the key is narrow, not broken.
Test the pushes
- Point a subscription at a request inspector (any service that shows incoming HTTP, or your own staging endpoint) and click Send test — or
POST /webhooks/{id}/test. - Check the
X-Filodos-Signatureagainst your secret with the example on the webhook events page before you trust any field. - Then wait for real activity: end a trip, drive a linked vehicle across a zone, or let the nightly send finish.
Diagnose errors
| You see | It means | Do this |
|---|---|---|
401 on every call | Expired sign-in token or revoked key. | Sign in again, or create a replacement key and revoke the old one. |
403 on one endpoint | The key lacks that scope. | Create a key with the scope, or narrow the feed to the granted ones. |
404 for a known id | Wrong id — or another organization's id. | Re-match against GET /devices of your own organization. |
422 on create | Blank name, unknown scope or event, bad URL. | Read the message; it names the field. |
Test ping 502 | Your endpoint is unreachable or too slow. | Expose it to the internet, accept POST, answer within 10 seconds. |
| No deliveries, no errors | Nothing fired: trips still open, vehicles unlinked to zones, or no driving. | Check the dashboard first — webhooks only push what the dashboard shows. |
Go-live checklist
- The key carries only the scopes the feed calls — verified with a
403probe. - The receiver checks every signature, stores delivery ids, and ignores repeats.
- The receiver answers within 10 seconds; the feed re-reads the API for anything missing (deliveries have no retries yet).
- Plate and driver matching runs against
GET /deviceson schedule, not from a stale copy. - A revoked test key from development stays revoked.