Webhook event payloads and delivery

All subscription deliveries share this envelope:

{"event":"generation.created","timestamp":"2026-09-28T10:00:00.000000Z","webhook_id":123,"data":{"id":789,"uuid":"example-generation-uuid","filename":"Payment documentation","generation_type":0,"generated_by_user":"[email protected]","created_at":"2026-09-28T10:00:00.000000Z","tag":null}}

Values above are illustrative. webhook_id identifies the subscription; data.id in this example identifies the generation. Verify the raw-body signature before reading either.

Supported events

Event Data
generation.created id, uuid, filename, generation_type, generated_by_user, created_at, tag
generation.updated Same generation identifiers and metadata, with updated_at
repository_sync.suggestions_ready Batch and Space identity, title, suggestion count/list, repository change context, review URL
repository_sync.suggestion_applied Suggestion and batch identity, target document, summary, content and action context
repository_sync.suggestion_discarded Suggestion and batch identity, target document, summary, content and action context

Generation events do not contain the full generated body. Fetch it with Get a generation using the numeric data.id. Updated events are not a promise that only the generated text changed.

For suggestions_ready, data includes batch_id, space_id, space_name, title, suggestions_count, suggestions, repository, review_url. Each suggestion includes id, type, target_name, summary, suggested_markdown, original_markdown. Repository context includes provider, identifier, branch, commit SHA/range and PR number. Fields can be null where no PR or previous page exists.

Delivery expectations

Return 2xx promptly. General subscription delivery currently makes one queue attempt per dispatched job; do not assume automatic exponential retries or guaranteed delivery. Reconcile important state through the API. Receiver response bodies stored in delivery logs are bounded to 2,000 characters; logs are not a complete archive of your response.

Treat documentation content in Autopilot events as sensitive. Avoid forwarding full payloads to public logs. Keep processing idempotent using an event-specific combination of resource identity and timestamp/state. See signature verification.

Lifecycle payloads identify the suggestion with suggestion_id, not id. They also include batch_id, space_id, space_name, suggestion_type, target_item (id, name), summary, suggested_markdown, original_markdown, and repository. Applied events include applied_by (id, email) and applied_at; discarded events use discarded_by and discarded_at.

Updated