Skip to content

Connect your systems with the API and webhooks

Create a read-only API key, subscribe an HTTPS endpoint to events and check each delivery.

In the app:API & webhooks

On this page

The customer API lets your own systems read Conduit TEM data. Webhooks tell those systems when a bill, finding, dispute or carrier order changes.

API keys always see the whole organization. A member’s location or cost-centre scope does not apply, so owners and admins manage access. Conduit staff can assist while helping with your organization.

API keys, webhook endpoints and the delivery log
API keys, webhook endpoints and the delivery log

Create an API key

  1. Open Settings → API & webhooks.
  2. Select Create API key.
  3. Give the key a name that identifies the receiving system.
  4. Choose only the scopes that system needs.
  5. Set an expiry when the integration is temporary.
  6. Select Create key, then copy it before closing the window.

The full key appears once. Conduit TEM stores a hash, its prefix and its last four characters. Use it as a Bearer token:

Authorization: Bearer ctem_…

The key is read-only and belongs to this organization. It never signs in as a member or as Conduit staff. The list shows when it was last used. Select Revoke to stop it immediately.

Add a webhook endpoint

  1. Select Add endpoint.
  2. Enter a name and the public HTTPS URL that receives events.
  3. Choose the events to send.
  4. Select Add endpoint, then copy the signing secret before closing the window.
  5. Select Send test and confirm the delivery is shown as Delivered.

Webhook URLs must use HTTPS on the public internet. Private, loopback, link-local and cloud metadata addresses are blocked after DNS resolution. Redirects are not followed. Every request has a ten-second total deadline and responses are capped in size.

Use Rotate secret if a signing secret may have been exposed. Copy the replacement before closing the window; the previous secret stops working immediately. Delete permanently removes the endpoint, its secret and its delivery log.

Verify a delivery

Read the request body as raw bytes before parsing JSON. The X-Conduit-Signature header looks like this:

t=1791381600,v1=7d8d…
  1. Reject the request if t is more than five minutes from your current time.
  2. Build the signed value as t, a period, then the exact raw request body.
  3. Compute its HMAC-SHA256 with the endpoint’s signing secret.
  4. Compare your hexadecimal digest with v1 using a constant-time comparison.

The request also includes X-Conduit-Event, X-Conduit-Event-Id and X-Conduit-Delivery-Id headers. Store the event id so a retry cannot apply the same change twice.

Understand retries and failures

A response from 200 through 299 succeeds. Other responses and network failures retry with backoff. The delivery log shows the final response code, duration and number of attempts.

After repeated deliveries fail completely, Conduit TEM disables the endpoint and emails the organization’s owners and admins. Fix the receiver, enable the endpoint and send a test event.

Successful event bodies are cleared from Conduit TEM after delivery. Delivery-log entries remain for 30 days, and API request audit entries remain for 90 days.

The complete endpoint, filter, pagination and event reference is public at /developers.