Workflows
Deliver a signed external event to an immutable Workflow Studio version
POST
/workflow-event-mesh/{source_uid}
Contract
Public webhook ingress authenticated with FinanceGPT HMAC v1 headers. The source is workspace-scoped, payloads are encrypted at rest, event IDs are idempotent, production sources pin immutable production workflow versions, and Marketplace-managed workflows cannot bypass Marketplace runtime controls through this endpoint.
Authentication
No global bearer requirement
Required scope
Operation-specific / public
Status
Published
Parameters
| Name | Location | Type | Required | Description |
|---|---|---|---|---|
source_uid |
path | string | Yes | — |
X-FinanceGPT-Event-Timestamp |
header | string | Yes | — |
X-FinanceGPT-Event-Id |
header | string | Yes | — |
X-FinanceGPT-Signature |
header | string | Yes | — |
Request body
application/json
·
required
[]
Code examples
These examples compose a request only. Public reference pages never transmit your credential or execute the operation.
curl
curl -X POST \
-H "Authorization: Bearer $FINANCEGPT_API_KEY" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
--data '[]' \
"https://financegpt.dev/api/v2/workflow-event-mesh/{source_uid}"
javascript
const response = await fetch("https:\/\/financegpt.dev\/api\/v2\/workflow-event-mesh\/{source_uid}", {
method: "POST",
headers: {
Authorization: `Bearer ${FINANCEGPT_API_KEY}`,
Accept: 'application/json',
'Content-Type': 'application/json',
},
body: JSON.stringify([]),
});
const data = await response.json();
python
import json
import os
import requests
response = requests.request(
'POST',
'https://financegpt.dev/api/v2/workflow-event-mesh/{source_uid}',
headers={
'Authorization': 'Bearer ' + os.environ['FINANCEGPT_API_KEY'],
'Accept': 'application/json',
},
json=json.loads('[]'),
)
response.raise_for_status()
print(response.json())
php
<?php
$ch = curl_init('https://financegpt.dev/api/v2/workflow-event-mesh/{source_uid}');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer '.getenv('FINANCEGPT_API_KEY'),
'Accept: application/json',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => json_encode(array (
)),
]);
$response = curl_exec($ch);
curl_close($ch);
echo $response;
Responses
| Status | Description |
|---|---|
202 |
Event accepted |
401 |
Signature |
404 |
Event source not found |
409 |
Event source inactive |
413 |
Event payload exceeds source limit |
422 |
Invalid event payload or signed-event headers |
429 |
Source rate limit reached |
503 |
Runtime temporarily busy; retry the same event ID |
Authority boundary
A developer credential proves application identity and permits only its scopes. It does not grant model promotion, policy override, QLM rebinding, or Financial Actions execution authority unless those separate controls are satisfied.