Files
zkldi_Tachi/old-docs/docs/api/webhooks/main.md
T
zk e363bd2532 docs: migrate from mkdocs to mdbook (#1558)
* docs: migrate from mkdocs to mdbook

- Rename old mkdocs docs/ to old-docs/ for reference
- Set up new docs/ with mdbook (book.toml + src/ tree)
- Mirror full nav structure from mkdocs.yml into SUMMARY.md
- Add Justfile-docs with docs-serve, docs-build, docs-check, docs-install recipes
- Import Justfile-docs from root Justfile
- Rewrite .github/workflows/docs.yml: build step uses taiki-e/install-action
  to install mdbook, split into separate build + deploy jobs, PR builds
  run the check step too

* ci(docs): pin actions to SHAs, install mdbook via release binary

* ci(docs): install mdbook from apt instead of curling a release binary

* dev: replace mkdocs python stack with mdbook in dev image

* ci(docs): apt only works on Debian; restore release binary install for Ubuntu CI

* docs: fix duplicate file entries in SUMMARY.md

* docs: remove docs-install recipe

* docs: remove site-url from book.toml to fix asset loading

* dev: install mdbook from upstream release binary, not Debian apt

The Debian package (0.4.x+ds) strips bundled font assets, leaving the
built site without fonts/fonts.css. Use the upstream tarball (same as CI)
so the theme is complete. Handles x86_64 and aarch64.

* docs: vendor mdbook tarballs in dev/mdbook/, install from there

Dockerfile.dev uses COPY + tar to install the right arch at build time.
CI extracts the x86_64 tarball directly from the checkout.
No network access required for either — and no stripped-fonts Debian package.

* fix: unwritten
2026-05-22 20:43:07 +01:00

34 lines
1.1 KiB
Markdown

# About Webhooks
Tachi supports webhooks. You can set a `webhookUri` as part of your
[Tachi API Client](../routes/clients.md).
## Usage and Security
When a given event happens on Tachi, your webhookUri will receive a POST
request with some content and the type of event.
You **MUST** validate that this request was from Tachi! Otherwise, anyone
could post fake data to your webhook URI and potentially compromise it.
To secure your webhook implementation, Tachi will send an Authorization header with `Bearer CLIENT_SECRET`. You should check that that value aligns with your client secret. If it doesn't, someone might be trying to perform an attack!
## Data Format
Data is sent as follows:
```json
{
"type": "EVENT_TYPE",
"content": {} // Content specific to that EVENT_TYPE!
}
```
The current Events are:
| Type | Description |
| :: | :: |
| `class-update/v1` | Fires whenever a user has had a class update positively, such as going from 9th Dan to 10th Dan. |
| `goal-achieved/v1` | Fires whenever a user has achieved a goal. |
| `quest-achieved/v1` | Fires whenever a user has achieved a quest. |