Skip to main content

Overview

Submit with batch=True and callback_url. Skip polling the predictions endpoint. VLM Run then:
  1. POSTs the full response to callback_url.
  2. Includes an HMAC signature when a webhook secret is set.

Setting Up Webhooks

1. Configure Your Webhook Secret

  1. Log in to your VLM Run Dashboard
  2. Navigate to Settings → API Keys
  3. Set your webhook secret (keep this secure and never share it)

2. Create a Webhook Endpoint

The endpoint must:
  • Accept POST requests
  • Verify the HMAC signature (recommended)
  • Process the webhook payload
  • Return a 2xx status code to acknowledge receipt

3. Submit Requests with Callback URL

Verifying Webhook Signatures

X-VLMRun-Signature carries an HMAC of the raw body. The key is your webhook secret. Verify the signature before processing the payload.
Verify the raw body before JSON parsing. On Express, use express.raw({ type: 'application/json' }). That keeps the body a Buffer.

Manual Verification (Alternative)

Webhook Delivery

Retry Logic

Failed deliveries retry with exponential backoff.
  • Maximum retries: 2 attempts
  • Timeout: 30 seconds per request
  • Backoff: Exponential (1s, 2s, 4s, etc.)
A delivery fails when:
  • The endpoint returns a non-2xx status code
  • The request times out after 30 seconds
  • A network connection error occurs

Testing Webhooks Locally

Expose a local endpoint with ngrok, Cloudflare Tunnel, or localtunnel. Use that public URL as callback_url.