Filodos

Testing your integration

There is no sandbox organization yet — test against your own organization with a narrow key, then widen it. Part of the documentation.

Test the reads

  1. Create a key with exactly the scopes your feed needs, for example devices:read and trips:read for mileage.
  2. Read the fleet, then one vehicle's trips:
    curl https://filodos.gr/filodos-dashboard/api/scoring/devices \
      -H "Authorization: Bearer filodos_…"
    curl 'https://filodos.gr/filodos-dashboard/api/scoring/trips?device_id=43' \
      -H "Authorization: Bearer filodos_…"
  3. Confirm a call outside the scopes reads 403 — that proves the key is narrow, not broken.

Test the pushes

  1. Point a subscription at a request inspector (any service that shows incoming HTTP, or your own staging endpoint) and click Send test — or POST /webhooks/{id}/test.
  2. Check the X-Filodos-Signature against your secret with the example on the webhook events page before you trust any field.
  3. Then wait for real activity: end a trip, drive a linked vehicle across a zone, or let the nightly send finish.

Diagnose errors

You seeIt meansDo this
401 on every callExpired sign-in token or revoked key.Sign in again, or create a replacement key and revoke the old one.
403 on one endpointThe key lacks that scope.Create a key with the scope, or narrow the feed to the granted ones.
404 for a known idWrong id — or another organization's id.Re-match against GET /devices of your own organization.
422 on createBlank name, unknown scope or event, bad URL.Read the message; it names the field.
Test ping 502Your endpoint is unreachable or too slow.Expose it to the internet, accept POST, answer within 10 seconds.
No deliveries, no errorsNothing fired: trips still open, vehicles unlinked to zones, or no driving.Check the dashboard first — webhooks only push what the dashboard shows.

Go-live checklist

  • The key carries only the scopes the feed calls — verified with a 403 probe.
  • The receiver checks every signature, stores delivery ids, and ignores repeats.
  • The receiver answers within 10 seconds; the feed re-reads the API for anything missing (deliveries have no retries yet).
  • Plate and driver matching runs against GET /devices on schedule, not from a stale copy.
  • A revoked test key from development stays revoked.