Skip to navigation

Trigger a CORA event

Defined, not yet published

Sends you an example delivery of a CORA event on demand, so you can test your receiver before the real flow sends you that event.

The request names the organizationId and the propertyId; both are required. Fortress checks that your API key owns them before sending anything.

Fortress takes the documented example payload of the requested event, gives it a fresh eventId and occurredAt, and POSTs it to every active webhook subscription of the property you name with partner key cora that lists the requested eventType in its eventTypes. Subscriptions of that property that do not list the event type, and those of other properties or organizations, do not receive it. Each delivery is signed with that subscription’s signing secret and uses the normal event envelope and X-Fortress-* headers, so your signature verification runs exactly as it will in production. Fortress makes one attempt per subscription and does not retry.

The response lists each subscription and the HTTP status your receiver answered with, or failed when no response was received or Fortress could not sign the delivery. The call returns once every delivery has finished: deliveries run in parallel, and the whole call is bounded by the gateway’s limit of about 29 seconds, so keep your receiver fast.

The payloads are examples, not real data. The ids in them do not point to records in your organization, so do not act on them (for example, do not read the application or write document results for it). This includes data.organizationId and data.propertyId: they are the documented example values, not the ones in your request. The event pages describe organizationId as always your own organization, so if your receiver checks it, verify the signature first and do not reject a test delivery on that check.

This route is defined for the CORA integration and is not delivered yet. Fortress does not serve it until it moves to Available. Authenticate with the x-api-key header; the key needs the webhooks permission with create. An all-organizations key works, as long as the property belongs to the organization you pass.

Authentication

x-api-keystring
API Key authentication via header

Request

This endpoint expects an object.
eventTypeenumRequired
The CORA event to send. Fortress sends that event's documented example payload. Any other value returns 400.
organizationIdstringRequiredformat: "uuid"
The organization whose property receives the example. The API key must own this organization, otherwise the call returns 404.
propertyIdstringRequiredformat: "uuid"

The property whose cora subscriptions that list eventType receive the example. It must belong to organizationId and the API key must own it, otherwise the call returns 404.

Response

Example sent. One entry per active cora subscription of the property that lists the event type, with the HTTP status your receiver answered with, or failed when no response was received or Fortress could not sign the delivery.

eventIdstringformat: "uuid"

The eventId of the example event. Fresh on every call; the same value is sent as eventId in the envelope and in the X-Fortress-Event-Id header.

deliverieslist of objects

One entry per active cora subscription of the property in the request that lists the event type.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
502
Bad Gateway Error