Skip to main content

nn-webhooks-sdk (Python)

Official Python SDK for NimbusNexus Webhooks — publish events, manage your endpoints / keys / deliveries, and verify the webhooks you receive.

pip install nn-webhooks-sdk

Verify an incoming webhook (subscribers)

When webhookd delivers a webhook it signs the body with your endpoint's signing secret. Always verify the signature before trusting the payload — it proves the request really came from webhookd and wasn't tampered with or replayed.

from nn_webhooks import verify

# In your webhook handler — pass the RAW request body bytes (do not re-serialize the JSON):
ok = verify(
    secret=ENDPOINT_SIGNING_SECRET,
    raw_body=request.body,
    signature=request.headers["X-Webhook-Signature"],
    timestamp=request.headers["X-Webhook-Timestamp"],
)
if not ok:
    return Response(status_code=400)  # forged, tampered, or outside the 300s replay window

Publish an event (producers)

from nn_webhooks import Client, WebhookdAPIError

with Client("https://webhooks.example.com", api_key="whsk_…") as wh:
    try:
        event = wh.publish(
            "order.created",
            {"order_id": "ord_123", "total": 4200},
            idempotency_key="order-123",   # makes the publish safe to retry
        )
        print(event.event_uid, event.deliveries_created)
    except WebhookdAPIError as e:
        print(e.status_code, e.code, e.message)   # the stable {error:{code,message}} envelope

Transient failures (connection errors, 429, 5xx) are retried with backoff (a 429 honours Retry-After); other 4xx raise WebhookdAPIError.

Targeting a project

A project is addressed by its ID ("prj_3f9a…") — it has no slug or short name. Every project-aware call takes an optional project_id; leave it unset to target your workspace's default project, which is what a single-project workspace always wants:

wh.publish("order.created", {...})                            # -> the workspace's default project
wh.publish("order.created", {...}, project_id="prj_3f9a…")    # -> that specific project

Only the server can resolve "the default project" — the id is opaque and per-workspace, so there is no client-side name for it. Omitting the field is the way to ask for it; passing a made-up string ("default", a project's display name) is a 404. The id you need is on any response — event.project_id, endpoint["project_id"] — or from GET /v1/projects.

Outbox / durable buffering (producers)

publish() calls webhookd synchronously — if webhookd is unreachable it raises and the event is lost. The write-first outbox decouples the two: enqueue() durably persists the event to a pluggable Store and returns IMMEDIATELY (no network); drain() (or a background drainer) ships the buffered events later. Every send carries Idempotency-Key = record.id, so a re-drain after a crash or a lost response never double-publishes — webhookd dedupes. Delivery is at-least-once: nothing is lost while webhookd is down.

from nn_webhooks import Client, SQLiteStore

# 1. Configure a durable store (survives process restarts).
store = SQLiteStore("outbox.db")

with Client("https://webhooks.example.com", api_key="whsk_…", store=store) as wh:
    # 2. enqueue() instead of publish() — writes to the store and returns at once, NO network call.
    record_id = wh.enqueue("order.created", {"order_id": "ord_123", "total": 4200})

    # 3a. Drain on demand (returns {"sent", "failed", "remaining"}):
    wh.drain()

    # 3b. …or run a background drainer that calls drain() every 5s until the client closes.
    wh.start_drainer(interval_seconds=5)
    # ... your app keeps enqueuing; the drainer ships in the background ...
    wh.stop_drainer()   # also called automatically by Client.close()/__exit__

Idempotency guarantee. record_id is the idempotency_key you pass (or a generated UUID v4) and becomes the Idempotency-Key header on every delivery attempt for that record. If the process crashes after a send but before the response is recorded, the next drain() re-sends with the same key and webhookd returns the original event without re-fanning-out. A record that keeps failing is retried with capped exponential backoff up to max_attempts (default 10), then flagged dead (never retried again) and handed to the optional on_dead callback.

Built-in stores — pick one for Client(..., store=...):

Store Durable? Extra needed
MemoryStore No (in-process) — (stdlib)
FileStore(dir) Yes (per-record JSON files) — (stdlib)
SQLiteStore(path) Yes (transactional) — (stdlib sqlite3)
RedisStore(url) Yes pip install 'nn-webhooks-sdk[redis]'
PostgresStore(dsn) Yes pip install 'nn-webhooks-sdk[postgres]'

The core SDK stays zero-dependency; RedisStore / PostgresStore lazily import their driver only when you construct them.

Schema change. The SQL stores' project column (a slug) is now project_id, nullable (null = the workspace's default project). There is no migration step — drain an outbox written by an older SDK before upgrading, or drop the webhookd_outbox table.

Manage endpoints, keys & deliveries (operators)

The same Client wraps the control-plane API — register receivers, mint keys, and drain the dead-letter queue from code (needs an admin-scoped key). Management methods return the raw JSON as dicts (snake_case, exactly as the API sends); list methods return a page — {"items": [...], "next_offset": int | None}; delete/revoke return None (a 204).

from nn_webhooks import Client

wh = Client("https://webhooks.example.com", api_key="whsk_admin_…")

# --- Endpoints ----------------------------------------------------------------
# Create a receiver — its signing secret is in the response exactly once, so persist it now.
ep = wh.create_endpoint(
    "https://your-app.example/webhooks",
    subscriptions=[{"match_kind": "prefix", "pattern": "order."}],
    description="orders service",
)
endpoint_id, signing_secret = ep["id"], ep["secret"]

wh.list_endpoints()                          # {"items": [...], "next_offset": ...} — default project
wh.list_endpoints(project_id="prj_3f9a…")    # …or scope the listing to one project by id
wh.get_endpoint(endpoint_id)

# PATCH — send only the keys you want to change (omitted = unchanged, None = cleared):
wh.update_endpoint(endpoint_id, {"max_attempts": 10, "status": "disabled"})

wh.rotate_endpoint_secret(endpoint_id)       # returns the new secret, once
wh.enable_endpoint(endpoint_id)              # recover an auto-disabled endpoint
wh.delete_endpoint(endpoint_id)              # -> None (204)

# --- API keys -----------------------------------------------------------------
key = wh.create_api_key("ci-publisher", scope="publish", expires_in_days=90)
print(key["key"])                            # shown once
wh.revoke_api_key(key["id"])                 # -> None (204)

# --- Deliveries / dead-letter recovery ----------------------------------------
for d in wh.list_deliveries(status="dead")["items"]:
    wh.redeliver(d["id"])

Develop

pip install -e '.[dev]'
pytest && ruff check . && mypy nn_webhooks

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

nn_webhooks_sdk-0.5.0.tar.gz (25.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

nn_webhooks_sdk-0.5.0-py3-none-any.whl (18.9 kB view details)

Uploaded Python 3

File details

Details for the file nn_webhooks_sdk-0.5.0.tar.gz.

File metadata

  • Download URL: nn_webhooks_sdk-0.5.0.tar.gz
  • Upload date:
  • Size: 25.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for nn_webhooks_sdk-0.5.0.tar.gz
Algorithm Hash digest
SHA256 22848660864f7b5c16113fc82b99214c5091e1b6ac066adb36115bf8e60f95c3
MD5 9a53e5d0d8874eab8f2d61e041cd5ca9
BLAKE2b-256 0f6e3e64aa962f0cb6b5fe91e19a8015aa035e32bb53aa3a6560bcbdbd8570f1

See more details on using hashes here.

Provenance

The following attestation bundles were made for nn_webhooks_sdk-0.5.0.tar.gz:

Publisher: publish.yml on NimbusNexus/Webhooks-sdks

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file nn_webhooks_sdk-0.5.0-py3-none-any.whl.

File metadata

File hashes

Hashes for nn_webhooks_sdk-0.5.0-py3-none-any.whl
Algorithm Hash digest
SHA256 cd6c2fc284a602b392dc114e1733523db46f8d3c92bd42decfb8a46adbf76b9c
MD5 7d1d5b78e2d1af6deae91534d562f40b
BLAKE2b-256 c9d4a03e1357c905e5cb888ad71304d55858aa1de5cc9484a91394aead6b08bc

See more details on using hashes here.

Provenance

The following attestation bundles were made for nn_webhooks_sdk-0.5.0-py3-none-any.whl:

Publisher: publish.yml on NimbusNexus/Webhooks-sdks

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.5.2

2 files

0.5.1

2 files

This release

0.5.0 This release

2 files

0.4.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page