PayFit Webhook

PayFit Webhook

Certified

Receive PayFit webhook events

Starts an execution when PayFit posts a Svix webhook. secret is the Svix signing secret (whsec_...) and is required. The request must include svix-id, svix-timestamp, and svix-signature, and the timestamp must be within five minutes. Events whose type does not match eventType return HTTP 204.

yaml
type: io.kestra.plugin.payfit.webhook.Webhook

Receive collaborator events

yaml
id: payfit_webhook
namespace: company.team

tasks:
  - id: log
    type: io.kestra.plugin.core.log.Log
    message: "PayFit event {{ trigger.eventType }}"

triggers:
  - id: payfit
    type: io.kestra.plugin.payfit.webhook.Webhook
    key: "{{ secret('PAYFIT_WEBHOOK_KEY') }}"
    secret: "{{ secret('PAYFIT_SVIX_SECRET') }}"
Properties
Min length1
Max length256

The unique key that will be part of the URL.

The key is used for generating the webhook URL.

::alert{type="warning"} Make sure to keep the webhook key secure. It's the only security mechanism to protect your endpoint from bad actors, and must be considered as a secret. You can use a random key generator to create the key. ::

Svix signing secret

Required Svix signing secret (whsec_...). The request is verified with the signature over svix-id.svix-timestamp.body. Requests without a valid signature are rejected.

Defaultfalse

Specifies whether a trigger is allowed to start a new execution even if a previous run is still in progress.

Event type to accept

When set, only JSON bodies whose event, eventType, type, or name equals this value start an execution.

DefaultFETCH
Possible Values
NONEFETCHSTORE

What the trigger does with the body of the webhook request.

  • FETCH: the body reaches the flow on the body output. A JSON body is deserialized, a binary one is base64-encoded. This is the default, and how a webhook has always behaved.
  • STORE: the body is streamed into Kestra's internal storage as it is received, and the flow reaches it through the uri output. Nothing of it travels through the execution, so this is the option to use for a large or binary payload - but note that a condition on the trigger can no longer read the body.
  • NONE: the body is read off the connection and dropped. Use it for a caller whose payload the flow does not need.

This only concerns the body of a request. The file parts of a multipart/form-data request are always stored in the internal storage and exposed on parts, whatever this property is set to, as a file part has no meaningful representation inside an execution.

The inputs to pass to the triggered flow

SubTypestring
Possible Values
CREATEDSUBMITTEDRUNNINGPAUSEDRESTARTEDKILLINGSUCCESSWARNINGFAILEDKILLEDCANCELLEDQUEUEDRETRYINGRETRIEDSKIPPEDBREAKPOINTRESUBMITTED

List of execution states after which a trigger should be stopped (a.k.a. disabled).

Defaulttrue

A condition that determines whether the trigger should run.

A Pebble expression evaluated at trigger time. The trigger fires only when the expression evaluates to a truthy value (true, a non-empty string, a non-zero number). Use this to gate trigger execution on dynamic runtime values such as execution labels, flow variables, or environment conditions.

Parsed JSON body, or the raw text when the body is not a JSON object

Event type taken from event, eventType, type, or name

SubTypearray

Request headers

SubTypearray

Query parameters