> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rigbox.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Receive signed webhooks

> A Flask inspector validates HMAC signatures and demonstrates required secrets plus generated credentials.

## Before you begin

Install the [CLI](/guides/install-cli), authenticate with `rig login`, and use an isolated test workspace. These examples require the v0.13 CLI. The manifests have been checked with the v0.13 parser; verify application health after deployment.

[Open the webhook-receiver source](https://github.com/rigbox-dev/rigbox-examples/tree/2612ffc9138d3b2f8169b10e3a54abd5495db8b8/webhook-receiver). These manifests explicitly select **incremental** deployment.

## Deploy from your machine

From a terminal on your machine, clone the repository and enter the example directory:

```bash theme={null}
git clone --branch codex/examples-docs-v013 https://github.com/rigbox-dev/rigbox-examples.git
cd rigbox-examples/webhook-receiver
rig --version
```

Supply `WEBHOOK_HMAC_KEY` through your shell or an ignored environment file. The committed demo value is for testing only. A missing required secret is a deployment configuration error.

Before deployment, run locally:

```bash theme={null}
export WEBHOOK_HMAC_KEY="$(openssl rand -hex 32)"
```

The generated credential uses a named map:

```yaml theme={null}
credentials:
  endpoint_token:
    generate: true
```

The process receives `CRED_ENDPOINT_TOKEN`; do not commit the generated value.

```bash theme={null}
rig deploy --strategy incremental
```

Record the workspace and app IDs printed by deployment. Use those exact IDs wherever this guide shows `WORKSPACE_ID` or `APP_ID`; do not guess a public URL from an app name.

## Verify the result

```bash theme={null}
rig app health --app APP_ID
rig app logs --app APP_ID
```

Use the dashboard’s Send test webhook control. Confirm a valid signature result; send a wrong signature to verify rejection. Recent events are held in memory and disappear when the process restarts.

## Access and recovery

The route defaults to private. The dashboard displays an endpoint token; do not expose the inspector publicly without reviewing its access model.

If deployment fails, read the terminal error and installation output before retrying. `rig app logs --app APP_ID --install` shows install logs when an app exists. Check required credentials, resource limits, the start command, and the configured health path. An image deployment may require explicit root-filesystem replacement consent; do not add `--reimage` to a workspace containing data you need.

## Clean up

After saving any data you need, delete only the isolated example workspace. This deletes its applications and workspace data; inspect persistent volumes and snapshots separately before removing them.

```bash theme={null}
rig workspace rm --workspace WORKSPACE_ID
```

Continue with [deployment guides](/guides/deploying) or [the manifest reference](/reference/rig-yaml).
