iMessage webhooks
Receive customer replies and delivery outcomes as signed HTTP events. SendiMessage posts to your endpoint when an inbound message arrives and when an outbound message reaches a final state.
How do iMessage webhooks work?
You register an endpoint and subscribe to events. When a customer replies, SendiMessage posts a signed receive event to your URL; when an outbound message reaches a final state, it posts an outbound event. Each delivery carries a SendiMessage-Signature header you verify before trusting the body.
Events
An inbound message arrived on one of your lines.
An outbound message reached a final state.
A line was blocked, or recovered.
Inbound payload
{"id": "evt_01j6x6z9k3f8v9m2n4p5q6r7s8","type": "receive","created_at": "2026-08-21T09:07:35+00:00","data": {"message": {"message_handle": "msg_01j6x6z6k3f8v9m2n4p5q6r7s8","direction": "inbound","from": "+14155550123","to": "+15555550100","text": "Can we move it to 3 PM?","channel": "imessage","status": "received","line_handle": "line_01j6x6yak3f8v9m2n4p5q6r7s8"}}}
Signatures
When a webhook has a secret configured, each delivery includes SendiMessage-Signature — the hex HMAC-SHA256 of the raw request body computed with your webhook secret. Verify against the exact raw bytes received using a constant-time comparison.
Delivery semantics
Each event is delivered as a signed POST with a 5-second timeout, retried on failure with exponential backoff; your response status beyond 2xx/non-2xx is not inspected. Treat webhooks as a low-latency hint and the API as the source of truth: everything an event carries is also queryable from GET /v2/messages (and GET /lines for block state), so a missed or delayed delivery is always recoverable by reconciliation.
FAQ
What signature header is used?
SendiMessage-Signature is the only signature header the API emits — in the form t={timestamp},v1={signature}, an HMAC-SHA256 of "{timestamp}.{raw body}" you verify with your webhook secret.
How do I test my endpoint?
Send a message and reply from a test recipient on your provisioned line, then verify the signature on the delivered event. See the webhook docs for verification code.
Implement webhooks
The full reference has verification examples in Node.js and Python.