Skip to content
adlicio.docs

API

Webhooks

Get a signed POST when brand research, audience research or a weekly report finishes, and verify each delivery with HMAC-SHA256.

Add an https endpoint from your account and pick the events to receive. We POST a JSON payload when each event fires.

Events#

EventWhen it fires
brand_research.completedA brand research run finished. data includes brand_id and brief_id.
audience_research.completedAn audience research run finished. data includes audience_id and brief_id.
brand_digest.completedA weekly report finished. data includes brand_id, digest_id, headline, new_comment_count, period_start and period_end.

Payload#

Example payload
{
  "id": "b2f8c1e0-...",
  "event": "brand_research.completed",
  "created_at": "2026-07-11T02:14:00.000Z",
  "data": {
    "brand_id": "…",
    "brand_name": "Acme",
    "brief_id": "…"
  }
}

Verify the signature#

Every delivery is signed. The X-Adlicio-Signature header is sha256= followed by the HMAC-SHA256 of the raw request body, keyed by your endpoint secret. Compare it against your own computation before you trust the payload. Retries reuse the same id, so dedupe on it.

Verify a signature (Node)
import crypto from "node:crypto";

// body is the RAW request bytes, secret is your "whsec_..." endpoint secret.
function verify(body, header, secret) {
  const expected =
    "sha256=" + crypto.createHmac("sha256", secret).update(body).digest("hex");
  return header === expected;
}