Webhooks
Register an HTTPS endpoint under Organisation settings, Integrations, choose the events, and Final Frame posts each one as it happens, signed, with retries. The delivery log shows every attempt and lets you redeliver.
Events
| Event | When |
|---|---|
| asset.received | A file landed on a deliverable and passed verification. |
| qc.passed | Automated quality control passed a deliverable. |
| qc.failed | Automated quality control failed a deliverable. |
| deliverable.status_changed | A deliverable moved to another status. |
| handoff.accepted | The receiving party accepted a handed-off project. |
| buyback.answered | A buyback request was answered. |
| workorder.created | A work order was raised. |
| rights.holding_recorded | Rights in were recorded on a work. |
| deal.closed | A deal was closed. Carries its close-out summary. |
| deal.reopened | A closed deal was opened again. Its close-out becomes provisional until it closes again. |
Payload
POST https://your.endpoint/path
webhook-id: 7f1c...
webhook-timestamp: 1791050000
webhook-signature: v1,base64(HMAC-SHA256(secret, "<id>.<timestamp>.<body>"))
content-type: application/json
{ "id": "7f1c...", "type": "qc.passed", "createdAt": "2026-10-03T19:10:00Z",
"organisationId": "...", "projectId": "...", "data": { ... } }Verifying
The signature follows the Standard Webhooks specification. Compute HMAC-SHA256 over <id>.<timestamp>.<raw body> with the secret shown when the endpoint was created (it begins whsec_), base64 it, and compare in constant time with the value after v1,. Reject timestamps older than five minutes. Answer with any 2xx within ten seconds; anything else is retried after 1 minute, 5 minutes, 30 minutes, 2 hours and 12 hours, after which the delivery is marked dead and can be redelivered by hand. An endpoint that fails fifty times in a row is disabled and says so.