Skip to main content
Workflows

Deliver a signed external event to an immutable Workflow Studio version

POST /workflow-event-mesh/{source_uid}

Contract

Public webhook ingress authenticated with FinanceGPT HMAC v1 headers. The source is workspace-scoped, payloads are encrypted at rest, event IDs are idempotent, production sources pin immutable production workflow versions, and Marketplace-managed workflows cannot bypass Marketplace runtime controls through this endpoint.

Authentication
No global bearer requirement
Required scope
Operation-specific / public
Status
Published

Parameters

Name Location Type Required Description
source_uid path string Yes
X-FinanceGPT-Event-Timestamp header string Yes
X-FinanceGPT-Event-Id header string Yes
X-FinanceGPT-Signature header string Yes

Request body

application/json · required
[]

Code examples

These examples compose a request only. Public reference pages never transmit your credential or execute the operation.

curl

curl -X POST \
  -H "Authorization: Bearer $FINANCEGPT_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  --data '[]' \
  "https://financegpt.dev/api/v2/workflow-event-mesh/{source_uid}"

javascript

const response = await fetch("https:\/\/financegpt.dev\/api\/v2\/workflow-event-mesh\/{source_uid}", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${FINANCEGPT_API_KEY}`,
    Accept: 'application/json',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify([]),
});
const data = await response.json();

python

import json
import os
import requests

response = requests.request(
    'POST',
    'https://financegpt.dev/api/v2/workflow-event-mesh/{source_uid}',
    headers={
        'Authorization': 'Bearer ' + os.environ['FINANCEGPT_API_KEY'],
        'Accept': 'application/json',
    },
    json=json.loads('[]'),
)
response.raise_for_status()
print(response.json())

php

<?php
$ch = curl_init('https://financegpt.dev/api/v2/workflow-event-mesh/{source_uid}');
curl_setopt_array($ch, [
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        'Authorization: Bearer '.getenv('FINANCEGPT_API_KEY'),
        'Accept: application/json',
        'Content-Type: application/json',
    ],
    CURLOPT_POSTFIELDS => json_encode(array (
)),
]);
$response = curl_exec($ch);
curl_close($ch);
echo $response;

Responses

Status Description
202 Event accepted
401 Signature
404 Event source not found
409 Event source inactive
413 Event payload exceeds source limit
422 Invalid event payload or signed-event headers
429 Source rate limit reached
503 Runtime temporarily busy; retry the same event ID

Authority boundary

A developer credential proves application identity and permits only its scopes. It does not grant model promotion, policy override, QLM rebinding, or Financial Actions execution authority unless those separate controls are satisfied.

Machine-readable sources