Webhooks
Mittis POSTs JSON events to your endpoint. Each request has an x-mittis-signature header in the form t=<unix>,v1=<hex>. The signature is an HMAC-SHA256 of {t}.{rawBody} using your endpoint secret. Reject anything older than five minutes.
Node · verify a signature
import { createHmac, timingSafeEqual } from 'node:crypto'; export function verify(secret, header, rawBody) { const { t, v1 } = Object.fromEntries(header.split(',').map(p => p.split('='))); if (Math.abs(Date.now() / 1000 - Number(t)) > 300) return false; const expected = createHmac('sha256', secret).update(`${t}.${rawBody}`).digest('hex'); return timingSafeEqual(Buffer.from(expected), Buffer.from(v1)); }
Event types
SMS
message.receivedA customer repliedSMS
message.statusDelivery state changedCALL
call.ringingInbound call started ringingCALL
call.completedAnswered call endedCALL
call.missedNobody answeredCALL
call.transcriptFinal transcript is readyEMAIL
email.deliveredAccepted by the recipient's serverEMAIL
email.openedRecipient opened itEMAIL
email.bouncedHard or soft bounce