# Webhooks

Recibí eventos de tu cuenta en tu propia URL, en tiempo real. Base: `https://panel.anunzi.net/api/v1/webhooks/`.

| Método | Ruta | Descripción |
| ------ | ---- | ----------- |
| `GET`  | `list.php` | Lista tus webhooks y los eventos disponibles. |
| `POST` | `set.php` | Crea o actualiza un webhook. |
| `POST` | `delete.php` | Elimina un webhook. |

***

## Eventos disponibles

- `lead.created` — se creó un contacto.
- `lead.updated` — se actualizó un contacto.
- `ticket.created` — se creó un ticket de soporte.
- `call.finished` — finalizó una llamada. *(También podés recibirlo por agente con `webhook_url` en [Agentes](agents.md).)*

## Suscribirse

```bash
curl -X POST "https://panel.anunzi.net/api/v1/webhooks/set.php" \
  -H "Authorization: Bearer anz_live_TU_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "url":"https://tu.app/anunzi-webhook", "events":["lead.created","ticket.created"] }'
```

Al crear, se devuelve un `secret` **una sola vez**. Podés suscribirte a todo con `"events":["*"]`.

## Verificar la firma

Cada entrega incluye estos encabezados:

```
X-Anunzi-Event: lead.created
X-Anunzi-Signature: sha256=<hmac>
```

La firma es `HMAC-SHA256` del cuerpo crudo usando tu `secret`. Verificala así (pseudocódigo):

```
firma_esperada = hmac_sha256(cuerpo_crudo, secret)
válida = ("sha256=" + firma_esperada) == header["X-Anunzi-Signature"]
```

## Cuerpo del evento

```json
{ "event": "lead.created", "data": { "id": 123, "name": "Ana", "phone": "+54911…" }, "sent_at": "2026-09-17T12:00:00Z" }
```

Respondé con `2xx`. Las entregas son best-effort (sin reintentos garantizados en esta versión).
