> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arc.cdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Webhook Connector

> Expose a public API endpoint for receiving HTTP POST and PUT data, with HMAC authentication, rate limiting, CORS support, and custom response scripting.

export const CommonCors = () => <>
    <table>
      <thead>
        <tr><th>Setting</th><th>Description</th></tr>
      </thead>
      <tbody>
        <tr>
          <td><strong>Enable cross-origin resource sharing (CORS)</strong></td>
          <td>Whether or not CORS is enabled. The rest of these options are only available when you check this box.</td>
        </tr>
        <tr>
          <td><strong>Allow all domains without '*'</strong></td>
          <td>If enabled, domain origins are not restricted to a specific list.</td>
        </tr>
        <tr>
          <td><strong>Access-Control-Allow-Origin</strong></td>
          <td>The comma-delimited list of domain origins to allow. Included as an HTTP response header.</td>
        </tr>
        <tr>
          <td><strong>Access-Control-Allow-Credentials</strong></td>
          <td>Whether or not user credentials such as cookies are allowed in cross-origin requests. Included as an HTTP response header.</td>
        </tr>
        <tr>
          <td><strong>Access-Control-Allow-Methods</strong></td>
          <td>The comma-delimited list of methods to allow. Included as an HTTP response header.</td>
        </tr>
        <tr>
          <td><strong>Access-Control-Allow-Headers</strong></td>
          <td>The comma-delimited list of headers to allow. Included as an HTTP response header.</td>
        </tr>
        <tr>
          <td><strong>Access-Control-Max-Age</strong></td>
          <td>The maximum duration (in seconds) that Access-Control response header values can be cached.</td>
        </tr>
      </tbody>
    </table>
  </>;

export const TrustedIp = () => <>
    <p>The following functions are available in the <strong>Trusted IP Addresses</strong> section:</p>

    <table>
      <thead>
        <tr><th>Function</th><th>Description</th></tr>
      </thead>
      <tbody>
        <tr><td><strong>Add</strong></td><td>Enter a new IP address range.</td></tr>
        <tr><td><strong>Edit</strong></td><td>Modify the selected IP address range.</td></tr>
        <tr><td><strong>Delete</strong></td><td>Deletes the selected IP address range from the list.</td></tr>
      </tbody>
    </table>

    <p>The following restrictions apply to this feature:</p>

    <ul style={{
  listStyleType: 'disc',
  paddingLeft: '1.5rem'
}}>
      <li style={{
  display: 'list-item'
}}><code>localhost</code> cannot be modified or removed from the list.</li>
      <li style={{
  display: 'list-item'
}}>Any IP addresses outside of the defined ranges are rejected.</li>
      <li style={{
  display: 'list-item'
}}>Ranges are supported. For example, the entry <code>100.10.100.1-15</code> indicates that IP addresses between <code>100.10.100.1</code> and <code>100.10.100.15</code> are allowed.</li>
      <li style={{
  display: 'list-item'
}}>Classless inter-domain routing (CIDR) notation is supported. For example, the entry <code>100.10.100.0/24</code> indicates that IP addresses between <code>100.10.100.0</code> and <code>100.10.100.255</code> are allowed.</li>
      <li style={{
  display: 'list-item'
}}>Wildcard patterns are supported. For example, the entry <code>100.10.100.*</code> indicates that IP addresses beginning with <code>100.10.100</code> are allowed.</li>
    </ul>

    <Note>
      <p>In order for clients to reach the server, a clear network path is required. In cloud environments you might need to make changes in three places:</p>
      <p style={{
  paddingLeft: '1.5rem',
  marginTop: '0.25rem',
  marginBottom: '0.25rem'
}}>• The networking rules in the cloud console.</p>
      <p style={{
  paddingLeft: '1.5rem',
  marginTop: '0.25rem',
  marginBottom: '0.25rem'
}}>• The firewall rules on the machine hosting the application. For example, when using an Amazon AMI, you might use an <em>Uncomplicated Firewall</em> (UFW) to allow traffic on the desired port. A common strategy in Linux environments is to forward traffic from ports lower than 1024 to a non-standard port higher than 1024, while configuring the application to use the non-standard port. This avoids permission issues associated with non-root users binding to ports lower than 1024.</p>
      <p style={{
  paddingLeft: '1.5rem',
  marginTop: '0.25rem',
  marginBottom: '0.25rem'
}}>• The <a href="/26.2/cloud/en/getting-started/administration/settings/network-access">Network Access</a> portion of the <a href="/26.2/cloud/en/getting-started/administration/settings/security">Security</a> tab.</p>
    </Note>
  </>;

export const SlasTab = ({siteName = "CData Arc"}) => <>
    <p><em>Settings related to configuring Service Level Agreements (SLAs).</em></p>
    <p>
      SLAs enable you to configure the volume you expect connectors in your flow to send or receive, and to set the time frame in which you expect that volume to be met. {siteName} sends emails to warn the user when an SLA is not met, and marks the SLA as <em>At Risk</em>, which means that if the SLA is not met soon, it will be marked as <em>Violated</em>. This gives the user an opportunity to step in and determine the reasons the SLA is not being met, and to take appropriate actions. If the SLA is still not met at the end of the at-risk time period, the SLA is marked as violated, and the user is notified again.
    </p>
    <p>
      To define an SLA, toggle <strong>Expected Volume</strong> on, then click the <strong>Settings</strong> tab.
    </p>
    <img src="/public/images/sla_empty.png" alt="SLA Empty" />
    <ul>
      <li>If your connector has separate send and receive actions, use the radio buttons to specify which direction the SLA pertains to.</li>
      <li>In the <strong>Expect at least</strong> portion of the window:
        <ul>
          <li>Set the minimum number of transactions you expect to be processed (the volume)</li>
          <li>Use the <strong>Every</strong> fields to specify the time frame</li>
          <li>Indicate when the SLA should go into effect. If you choose <strong>Starting on</strong>, complete the date and time fields.</li>
          <li>Check the boxes for the days of the week that you want the SLA to be in effect. Use the dropdown to choose <strong>Everyday</strong> if necessary.</li>
        </ul>
      </li>
      <li>In the <strong>Set status to 'At Risk'</strong> portion of the window, specify when the SLA should be marked as at risk.
        <ul>
          <li>By default, notifications are not sent until an SLA is in violation. To change that, check <strong>Send an 'At Risk' notification</strong>.</li>
        </ul>
      </li>
    </ul>
    <p>
      The following example shows an SLA configured for a connector that expects to receive 1000 files every day Monday-Friday. An at-risk notification is sent 1 hour before the end of the time period if the 1000 files have not been received.
    </p>
    <img src="/public/images/sla_defined.png" alt="SLA Configuration Example" />
    <Note>
      You can turn off SLA alerts if necessary. This can be useful during maintenance windows. Click <strong>Settings</strong> on the navbar, then navigate to <strong>Alerts &gt; General Alerts</strong>. Click the tablet and pencil icon to edit, and uncheck the <strong>SLA Alerts</strong> setting.
    </Note>
  </>;

export const AlertsTab = ({siteNameShort = "Arc"}) => <>
    <p><em>Settings related to configuring alerts.</em></p>
    <p>
      Before you can execute Service Level Agreements (SLAs), you need to set up email alerts for notifications. By default, {siteNameShort} uses the global settings on the <a href="/26.2/cloud/en/getting-started/administration/settings/alerts">Alerts</a> tab. To use other settings for this connector, toggle <strong>Override global setting</strong> on.
    </p>
    <p>
      By default, error alerts are enabled, which means that emails are sent whenever there is an error. To turn them off, uncheck the <strong>Enable</strong> checkbox.
    </p>
    <p>
      Enter a <strong>Subject</strong> (mandatory), then optionally enter a comma-separated list of <strong>Recipient</strong> emails.
    </p>
  </>;

export const MiscConnector = () => <>
    <p><em>Miscellaneous settings are for specific use cases.</em></p>
    <table>
      <thead>
        <tr>
          <th>Setting</th>
          <th>Description</th>
        </tr>
      </thead>
      <tbody>
        <tr>
          <td><strong>Other Settings</strong></td>
          <td>Enables you to configure hidden connector settings in a semicolon-separated list (for example, <code>setting1=value1;setting2=value2</code>). Normal connector use cases and functionality should not require the use of these settings.</td>
        </tr>
      </tbody>
    </table>
  </>;

export const Logging = () => <>
    <p><em>Settings that govern the creation and storage of logs.</em></p>
    <table>
      <thead>
        <tr>
          <th>Setting</th>
          <th>Description</th>
        </tr>
      </thead>
      <tbody>
        <tr>
          <td><strong>Log Level</strong></td>
          <td>The verbosity of logs generated by the connector. When you request support, set this to <strong>Debug</strong>.</td>
        </tr>
        <tr>
          <td><strong>Log Subfolder Scheme</strong></td>
          <td>Instructs the connector to group files in the Logs folder according to the selected interval. The <strong>Weekly</strong> option (which is the default) instructs the connector to create a new subfolder each week and store all logs for the week in that folder. Leaving this setting blank tells the connector to save all logs directly in the Logs folder. For connectors that process many transactions, using subfolders helps keep logs organized and improves performance.</td>
        </tr>
        <tr>
          <td><strong>Log Messages</strong></td>
          <td>Check this to have the log entry for a processed file include a copy of the file itself. If you disable this, you might not be able to download a copy of the file from the <strong>Transactions</strong> tab.</td>
        </tr>
      </tbody>
    </table>
  </>;

export const MacrosExamples = ({extraMacros = []}) => <>
    <p>
      Some macros, such as %Ext% and %ShortDate%, do not require an argument, but others do. All
      macros that take an argument use the following syntax: <code>%Macro:argument%</code>
    </p>

    <p>Here are some examples of the macros that take an argument:</p>

    <ul>
      <li>%Header:headername%: Where <code>headername</code> is the name of a header on a message.</li>
      <li>%Header:mycustomheader% resolves to the value of the <code>mycustomheader</code> header set on the input message.</li>
      <li>%Header:ponum% resolves to the value of the <code>ponum</code> header set on the input message.</li>
      <li>%RegexFilename:pattern%: Where <code>pattern</code> is a regex pattern. For example, <code>%RegexFilename:^([\w][A-Za-z]+)%</code> matches and resolves to the first word in the filename and is case insensitive (<code>test_file.xml</code> resolves to <code>test</code>).</li>
      <li>%Vault:vaultitem%: Where <code>vaultitem</code> is the name of an item in the <a href="/26.2/cloud/en/getting-started/administration/settings/global-settings-vault">vault</a>. For example, <code>%Vault:companyname%</code> resolves to the value of the <code>companyname</code> item stored in the vault.</li>
      <li>%DateFormat:format%: Where <code>format</code> is an accepted date format (see <a href="/26.2/cloud/en/scripting/value-formatters/date-formatters#sample-date-formats">Sample Date Formats</a> for details). For example, <code>%DateFormat:yyyy-MM-dd-HH-mm-ss-fff%</code> resolves to the date and timestamp on the file.</li>
      {extraMacros.filter(item => item.example).map(item => <li key={`ex-${item.name}`}>{item.example}</li>)}
    </ul>

    <p>You can also create more sophisticated macros, as shown in the following examples:</p>

    <ul>
      <li>Combining multiple macros in one filename: <code>%DateFormat:yyyy-MM-dd-HH-mm-ss-fff%%EXT%</code></li>
      <li>Including text outside of the macro: <code>MyFile_%DateFormat:yyyy-MM-dd-HH-mm-ss-fff%</code></li>
      <li>Including text within the macro: <code>%DateFormat:'DateProcessed-'yyyy-MM-dd_'TimeProcessed-'HH-mm-ss%</code></li>
    </ul>
  </>;

export const MacrosTable = ({siteName = "CData Arc", extraMacros = []}) => <>
    <p>
      Using macros in file naming strategies can enhance organizational efficiency and contextual
      understanding of data. By incorporating macros into filenames, you can dynamically include
      relevant information such as identifiers, timestamps, and header information, providing
      valuable context to each file.
    </p>

    <p>{siteName} supports these macros, which all use the following syntax: <code>%Macro%</code>.</p>

    <table>
      <thead>
        <tr><th>Macro</th><th>Description</th></tr>
      </thead>
      <tbody>
        <tr><td>ConnectorID</td><td>Evaluates to the ConnectorID of the connector.</td></tr>
        <tr><td>Ext</td><td>Evaluates to the file extension of the file currently being processed by the connector.</td></tr>
        <tr><td>Filename</td><td>Evaluates to the filename (extension included) of the file currently being processed by the connector.</td></tr>
        <tr><td>FilenameNoExt</td><td>Evaluates to the filename (without the extension) of the file currently being processed by the connector.</td></tr>
        <tr><td>MessageId</td><td>Evaluates to the MessageId of the message being output by the connector.</td></tr>
        <tr><td>RegexFilename:<em>pattern</em></td><td>Applies a RegEx pattern to the filename of the file currently being processed by the connector.</td></tr>
        <tr><td>Header:<em>headername</em></td><td>Evaluates to the value of a targeted header (<code>headername</code>) on the current message being processed by the connector.</td></tr>
        <tr><td>LongDate</td><td>Evaluates to the current datetime of the system in long-handed format (for example, Wednesday, January 24, 2024).</td></tr>
        <tr><td>ShortDate</td><td>Evaluates to the current datetime of the system in a yyyy-MM-dd format (for example, 2024-01-24).</td></tr>
        <tr><td>DateFormat:<em>format</em></td><td>Evaluates to the current datetime of the system in the specified format (<code>format</code>). See <a href="/26.2/cloud/en/scripting/value-formatters/date-formatters#date-formats-with-literal-characters">Sample Date Formats</a> for the available datetime formats.</td></tr>
        <tr><td>Vault:<em>vaultitem</em></td><td>Evaluates to the value of the specified vault item.</td></tr>
        {extraMacros.map(item => <tr key={item.name}>
            <td>{item.name}</td>
            <td>{item.description}</td>
          </tr>)}
      </tbody>
    </table>
  </>;

export const companyName = "CData";

export const siteNameShort = "Arc";

export const siteName = "CData Arc";

Webhook connectors support exposing a public API endpoint.

## Key Capabilities

* Public API endpoint exposure for HTTP POST and PUT data ingestion with modern authentication mechanisms
* User-based rate limiting and concurrent request management with CORS support
* HMAC signature authentication for enhanced security and custom response event scripting
* Sample request templates for [XML Map](./xml-map/xml-map) connector integration and workflow automation

## Overview

Webhook connectors enable data to enter the {siteName} flow via HTTP POSTs and PUTs. Each Webhook connector exposes an endpoint in the application where external clients can send XML and JSON payloads. These payloads are written to an output file and passed along to the next connectors in the flow.

You can specify a sample request in the Webhook connector to simplify the process of transforming data that is POSTed to the endpoint. When an XML sample is specified, and the Webhook connector is connected to an XML Map connector in the flow, the XML Map connector automatically detects the expected structure of XML files posted to the endpoint. You can then use the XML Map connector [Node Value Editor](../mapping/mapping-node-value-editor) to map this structure into a target XML structure.

## Connector Configuration

This section contains all of the configurable connector properties.

### Settings Tab

#### Connector Details

*Settings related to the core operation of the connector.*

| Setting                   | Description                                                                                     |
| ------------------------- | ----------------------------------------------------------------------------------------------- |
| **Connector Id**          | The static, unique identifier for the connector.                                                |
| **Connector Type**        | Displays the connector name and a description of what it does.                                  |
| **Connector Description** | An optional field to provide a free-form description of the connector and its role in the flow. |
| **Webhook Endpoint**      | The generated URL (based on the connector name) where the endpoint is exposed.                  |

#### Advanced Settings

| Setting                        | Description                                                                                                                                                                                                                             |
| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Local File Scheme**          | A scheme for assigning filenames to messages that are output by the connector. You can use macros in your filenames dynamically to include information such as identifiers and timestamps. For more information, see [Macros](#macros). |
| **Enable HMAC Authentication** | Check **Enabled** to use HMAC (Hash-based Message Authentication Code) signature authentication to verify the authenticity and integrity of webhook requests. See [HMAC Authentication](#hmac-authentication) for details.              |
| **HMAC Signature Header**      | The signature header value. By default this is `x-cdata-hmac-signature`, but you can customize it.                                                                                                                                      |

### Request Details Tab

Supply an XML or JSON template representing the expected structure of incoming data. The primary benefit of specifying a sample request is when you connect the Webhook connector to an [XML Map](./xml-map/xml-map) connector in the flow. Use XML Map connectors when the API data needs to be converted into some other format, like an EDI document or a database insert.

The XML Map connector detects the XML structure of the sample request and uses this as the **Source File** for the XML Map connector. Upload the XML structure representing the target format as the **Destination File**, then use the Node Value Editor to convert the source structure into the destination.

### Users Tab

The **Users** tab lets you:

* Create users with their associated authtokens and OAuth 2.0 credentials
* Define POST and/or PUT privileges
* Specify how many requests each user can make per hour
* Specify how many concurrent requests are permitted

You can add, edit, and delete users on this tab. See Add or Edit Users for details on each field.

<Note>The request settings here override settings in the [Default Rate Limits](#default-rate-limits-per-user) section of the **Server** tab.</Note>

### Server Tab

#### Trusted IP Addresses

<TrustedIp />

#### Default Rate Limits (Per User)

*Settings restricting the number of requests allowed, if no values have been provided on the Users tab.*

| Setting                     | Description                                                             |
| --------------------------- | ----------------------------------------------------------------------- |
| **Max Requests Per Hour**   | The limit to the number of requests a single user can issue in an hour. |
| **Max Concurrent Requests** | The limit to the number of concurrent requests a user can issue.        |

#### Cross-Origin Resource Sharing (CORS)

*Settings governing the use of CORS to serve cross-origin resources.*

<CommonCors />

#### Advanced Settings

| Setting              | Description                                                                                                                                                                                                                    |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Authtoken in URL** | Check this to allow the connector to pass the authtoken in query string parameters for authentication. See [Using Auth Tokens as Query String Parameters](#using-auth-tokens-as-query-string-parameters) for more information. |

### Advanced Tab

#### Logging

<Logging />

#### Miscellaneous

<MiscConnector />

### Alerts Tab

<AlertsTab />

### SLAs Tab

<SlasTab />

## HMAC Authentication

HMAC (Hash-based Message Authentication Code) signature authentication is a cryptographic method that verifies the authenticity and integrity of webhook requests. It uses a shared secret key to generate a unique signature for each request, ensuring:

* Request Authenticity: Confirms the request originated from a trusted source
* Data Integrity: Verifies that the request payload hasn't been tampered with during transmission
* Replay Attack Prevention: Protects against malicious reuse of intercepted requests

This provides significantly stronger security compared to traditional authentication methods like basic authentication or API keys, which can be more easily compromised.

Users with Professional or Enterprise [licenses](../getting-started/administration/settings/license-settings) can enable HMAC signature authentication for incoming webhook requests.

### Configuration

<Warning>HMAC authentication is a global setting that applies to every user authorized to access the webhook.</Warning>

1. Enable HMAC Authentication
   1. Check **Enable HMAC Authentication** in the webhook connector settings.
   2. Optionally, customize the HMAC Signature Header value (the default is `x-cdata-hmac-signature`).

### Set HMAC Keys for Users

After enabling HMAC authentication:

1. Navigate to the **Users** tab of the webhook connector.
2. Configure the HMAC key each authorized webhook user:
   1. An HMAC key is automatically generated for each user. You can override the auto-generated key with a custom value. Each user must use their assigned HMAC key to generate valid signatures for their webhook requests.

## Auth Token Authentication

Users can access Webhook resources by providing authtokens with requests. Manage users and authtokens by adding or editing a user on the [Users](#users-tab) tab, and navigating to the **Authentication** tab.

Before users can call the Webhook endpoint, you must also set trusted IP addresses for connections. Set these in the [Trusted IP Addresses](#trusted-ip-addresses) section of the **Server** tab. By default, all IP addresses are restricted.

### Using Auth Tokens in Basic Authentication

Enter the user's authtoken as the password when using Basic Authentication.

### Using Auth tokens in the HTTP Header

Add the HTTP header `x-{companyName}-authtoken` with the authtoken as part of the HTTP request.

### Using Auth Tokens as Query String Parameters

To allow the connector to pass the authtoken in query string parameters, check **Allow authtoken in URL** in the [Advanced Settings](#advanced-settings) section of the **Server** tab.

After enabling this feature, you can specify the authtoken as the value of the `@authtoken` parameter, which you supply as part of the HTTP form-post data or as a query parameter.

## OAuth 2.0 Authentication

Users can secure Webhook resources using OAuth 2.0 authentication. Manage users and OAuth credentials by adding or editing a user on the [Users](#users-tab) tab, and navigating to the **Authentication** tab.

## Receiving Data

When data is uploaded to the webhook endpoint, the body of the web request is written as an output file and passed along to the next connector in the flow. This allows for a flexible method of invoking an {siteNameShort} workflow via an external API call.

<Tip>Data uploaded to the endpoint is not validated in the Webhook connector, and should be validated later in the flow if necessary.</Tip>

## Custom Responses

Ordinarily, the Webhook connector accepts the post data with a token response that the request was accepted, but you can customize the response by using the `Response` event, where the `_request`, `_httpheaders`, `_response`, and `_message` special items are available. When specified, the connector expects the custom response to be provided through the `_response` item.

You can also use the `Response` event to push custom output items using the following attributes:

* Filename: The filename of the output message to pass down the flow.
* Data: The data to include in the message that is passed down the flow. For binary data, use the Base64Data attribute instead.
* Base64Data: The Base64-encoded data to include in the message that is passed down the flow.
* HeaderNames#: A list of header names to include on the message that is passed down the flow. Use the HeaderValues attribute to specify values for these headers at the matching index.
* HeaderValues#: A list of header values to include on the message that is passed down the flow. These values are used for the header names defined at the matching index in the HeaderNames list.
* Logs#: A list of log entries to include in the logs for the transaction.

### Response Examples

To push a file containing the body of the webhook request, with a custom filename and header, down the flow, the {siteNameShort}Script in the `Response` event might look like this:

```xml theme={null}
<arc:set attr="out.Filename" value="MyCustomFilename.xml" />
<arc:set attr="out.Data" value="[_message.body]" />
<arc:set attr="out.HeaderNames#1" value="MyHeader1" />
<arc:set attr="out.HeaderValue#1" value="MyHeader1Value" />
<arc:push item="out" />
```

To surface a header on the incoming request as a header on the message that is passed down the flow, the {siteNameShort}Script in the `Response` event might look like this:

```xml theme={null}
<arc:set attr="_message.header:MySpecialHeader" value="[_httpheaders.MyWebhookHeader]" />
<arc:set attr="_response.header:Content-Type" value="application/xml" />
<arc:set attr="_response.write" value="<Status>Successfully processed message with MySpecialHeader=[_message.header:MySpecialHeader]</Status>" />
```

With the {siteNameShort}Script above in the `Response` event, a client can send a request similar to the following:

```http theme={null}
POST https://localhost/connector/Webhook1/webhook.rsb HTTP/1.1
content-type: application/xml
X-{siteNameShort}-Authtoken: 1s7U4w0a2P3l8v9W3l0q
MyWebhookHeader: Hello World!

<Items>
  <Webhook>Hello World!</Webhook>
</Items>
```

and receive the following response:

```http theme={null}
HTTP/1.1 200 OK
Connection: close
Date: Tue, 31 Aug 2021 19:16:13 GMT
X-Frame-Options: SAMEORIGIN
Content-Type: application/xml
Content-Length: 81
Server: Jetty(9.4.z-SNAPSHOT)

<Status>Successfully processed message with MySpecialHeader=Hello World!</Status>
```

## Macros

<MacrosTable />

### Examples

<MacrosExamples />
