cURL
curl -X POST https://api.bizmori.com/api/v2/orders/webhooks \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "My Webhook",
"url": "https://example.com/webhook"
}'const response = await fetch('https://api.bizmori.com/api/v2/orders/webhooks', {
method: 'POST',
headers: {
'Authorization': 'Bearer YOUR_API_TOKEN',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'My Webhook',
url: 'https://example.com/webhook'
})
});
const data = await response.json();
// Save data.data.secret securely — it won't be shown againimport requests
response = requests.post(
'https://api.bizmori.com/api/v2/orders/webhooks',
headers={'Authorization': 'Bearer YOUR_API_TOKEN'},
json={
'name': 'My Webhook',
'url': 'https://example.com/webhook'
}
)
data = response.json()
# Save data['data']['secret'] securely — it won't be shown again<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.bizmori.com/api/v2/orders/webhooks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://example.com/webhook',
'name' => '<string>',
'isTest' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.bizmori.com/api/v2/orders/webhooks"
payload := strings.NewReader("{\n \"url\": \"https://example.com/webhook\",\n \"name\": \"<string>\",\n \"isTest\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.bizmori.com/api/v2/orders/webhooks")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://example.com/webhook\",\n \"name\": \"<string>\",\n \"isTest\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.bizmori.com/api/v2/orders/webhooks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://example.com/webhook\",\n \"name\": \"<string>\",\n \"isTest\": true\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": 123,
"name": "<string>",
"secret": "<string>",
"isTest": true
}
}{
"code": "VALIDATION_FAILED"
}{
"code": "AUTH_NOT_AUTHENTICATED"
}{
"code": "AUTH_FORBIDDEN"
}Webhooks
Create webhook
Register a new webhook. A test API key creates an owned test endpoint when isTest is omitted or true; isTest: false returns AUTH_FORBIDDEN.
- Multiple webhooks can be registered
- A signing secret is returned upon registration
Important: The secret is only shown in this response. Store it securely.
Webhook Event Types
| Event Type | Description |
|---|---|
order.antiAi.completed | Anti-AI processing completed |
order.antiAi.failed | Anti-AI processing failed |
order.watermarkEmbed.completed | Watermark embedding completed |
order.watermarkEmbed.failed | Watermark embedding failed |
order.watermarkExtract.completed | Watermark extraction completed |
order.watermarkExtract.failed | Watermark extraction failed |
Signature Verification
Webhook requests include an X-MoriBiz-Signature header.
The signature is generated using HMAC-SHA256 with the secret issued at registration.
const crypto = require('crypto');
const signature = crypto.createHmac('sha256', secret)
.update(JSON.stringify(payload))
.digest('hex');
Retry Policy
- Max 3 retries
- Exponential backoff (1s, 2s, 4s)
- Success response: 2xx status code
Set isTest to true for a test webhook endpoint. Test API keys can manage only test endpoints owned by the same owner.
POST
/
api
/
v2
/
orders
/
webhooks
cURL
curl -X POST https://api.bizmori.com/api/v2/orders/webhooks \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "My Webhook",
"url": "https://example.com/webhook"
}'const response = await fetch('https://api.bizmori.com/api/v2/orders/webhooks', {
method: 'POST',
headers: {
'Authorization': 'Bearer YOUR_API_TOKEN',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'My Webhook',
url: 'https://example.com/webhook'
})
});
const data = await response.json();
// Save data.data.secret securely — it won't be shown againimport requests
response = requests.post(
'https://api.bizmori.com/api/v2/orders/webhooks',
headers={'Authorization': 'Bearer YOUR_API_TOKEN'},
json={
'name': 'My Webhook',
'url': 'https://example.com/webhook'
}
)
data = response.json()
# Save data['data']['secret'] securely — it won't be shown again<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.bizmori.com/api/v2/orders/webhooks",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://example.com/webhook',
'name' => '<string>',
'isTest' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.bizmori.com/api/v2/orders/webhooks"
payload := strings.NewReader("{\n \"url\": \"https://example.com/webhook\",\n \"name\": \"<string>\",\n \"isTest\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.bizmori.com/api/v2/orders/webhooks")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://example.com/webhook\",\n \"name\": \"<string>\",\n \"isTest\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.bizmori.com/api/v2/orders/webhooks")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://example.com/webhook\",\n \"name\": \"<string>\",\n \"isTest\": true\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": 123,
"name": "<string>",
"secret": "<string>",
"isTest": true
}
}{
"code": "VALIDATION_FAILED"
}{
"code": "AUTH_NOT_AUTHENTICATED"
}{
"code": "AUTH_FORBIDDEN"
}Authorizations
Bearer API key for external client access. Live keys use the sk_ prefix; test keys use the sk_test_ prefix and support order-lifecycle testing with mock responses without processing or credit usage.
Body
application/json