curl --request POST 'https://gyra-core.gyramais.com.br/v1/webhook/endpoints' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{"url":"https://api.suaempresa.com/gyra/webhook","label":"Produção, esteira de crédito","events":["registry.document.assessed","collection.completed","collection.message.failed"],"enabled":true}'const resposta = await fetch("https://gyra-core.gyramais.com.br/v1/webhook/endpoints", {
method: "POST",
headers: {
Authorization: `Bearer ${token}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"url": "https://api.suaempresa.com/gyra/webhook",
"label": "Produção, esteira de crédito",
"events": [
"registry.document.assessed",
"collection.completed",
"collection.message.failed"
],
"enabled": true
}),
});
const dados = await resposta.json();
import requests
resposta = requests.post(
"https://gyra-core.gyramais.com.br/v1/webhook/endpoints",
headers={"Authorization": f"Bearer {token}"},
json={
"url": "https://api.suaempresa.com/gyra/webhook",
"label": "Produção, esteira de crédito",
"events": [
"registry.document.assessed",
"collection.completed",
"collection.message.failed"
],
"enabled": True
},
)
dados = resposta.json()
<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://gyra-core.gyramais.com.br/v1/webhook/endpoints",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://api.suaempresa.com/gyra/webhook',
'label' => 'Produção, esteira de crédito',
'events' => [
'registry.document.assessed',
'collection.completed',
'collection.message.failed'
],
'enabled' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://gyra-core.gyramais.com.br/v1/webhook/endpoints"
payload := strings.NewReader("{\n \"url\": \"https://api.suaempresa.com/gyra/webhook\",\n \"label\": \"Produção, esteira de crédito\",\n \"events\": [\n \"registry.document.assessed\",\n \"collection.completed\",\n \"collection.message.failed\"\n ],\n \"enabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://gyra-core.gyramais.com.br/v1/webhook/endpoints")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://api.suaempresa.com/gyra/webhook\",\n \"label\": \"Produção, esteira de crédito\",\n \"events\": [\n \"registry.document.assessed\",\n \"collection.completed\",\n \"collection.message.failed\"\n ],\n \"enabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://gyra-core.gyramais.com.br/v1/webhook/endpoints")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://api.suaempresa.com/gyra/webhook\",\n \"label\": \"Produção, esteira de crédito\",\n \"events\": [\n \"registry.document.assessed\",\n \"collection.completed\",\n \"collection.message.failed\"\n ],\n \"enabled\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "6612a7f30000000000000091",
"url": "https://api.suaempresa.com/gyra/webhook",
"label": "Produção, esteira de crédito",
"events": [
"registry.document.assessed",
"collection.completed",
"collection.message.failed"
],
"enabled": true,
"secretHint": "…a91f4c",
"secret": "whsec_4f1c9e2b7a6d3058c1e2f4a9b8d7c6e5f0a1b2c3d4e5f60718293a4b5ca91f4c",
"createdAt": "2026-09-05T18:40:00.000Z",
"organizationId": "6612a7f30000000000000009",
"consecutiveFailures": 0,
"lastDeliveryStatus": null,
"lastDeliveryError": null,
"lastDeliveryAt": null,
"updatedAt": "2026-09-06T10:12:00.000Z"
}{
"code": 400,
"message": "url must be a URL address"
}{
"code": 401,
"message": "Token de acesso inválido."
}{
"code": 403,
"message": "Você não tem permissão para acessar este recurso."
}{
"code": 404,
"message": "Assinatura de webhook não encontrada."
}{
"code": 500,
"message": "Internal server error"
}{
"code": 502,
"message": "Não foi possível salvar a assinatura."
}Criar ou Atualizar Assinatura
Para assinar os eventos do módulo e parar de fazer polling.
curl --request POST 'https://gyra-core.gyramais.com.br/v1/webhook/endpoints' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{"url":"https://api.suaempresa.com/gyra/webhook","label":"Produção, esteira de crédito","events":["registry.document.assessed","collection.completed","collection.message.failed"],"enabled":true}'const resposta = await fetch("https://gyra-core.gyramais.com.br/v1/webhook/endpoints", {
method: "POST",
headers: {
Authorization: `Bearer ${token}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
"url": "https://api.suaempresa.com/gyra/webhook",
"label": "Produção, esteira de crédito",
"events": [
"registry.document.assessed",
"collection.completed",
"collection.message.failed"
],
"enabled": true
}),
});
const dados = await resposta.json();
import requests
resposta = requests.post(
"https://gyra-core.gyramais.com.br/v1/webhook/endpoints",
headers={"Authorization": f"Bearer {token}"},
json={
"url": "https://api.suaempresa.com/gyra/webhook",
"label": "Produção, esteira de crédito",
"events": [
"registry.document.assessed",
"collection.completed",
"collection.message.failed"
],
"enabled": True
},
)
dados = resposta.json()
<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://gyra-core.gyramais.com.br/v1/webhook/endpoints",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'url' => 'https://api.suaempresa.com/gyra/webhook',
'label' => 'Produção, esteira de crédito',
'events' => [
'registry.document.assessed',
'collection.completed',
'collection.message.failed'
],
'enabled' => true
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://gyra-core.gyramais.com.br/v1/webhook/endpoints"
payload := strings.NewReader("{\n \"url\": \"https://api.suaempresa.com/gyra/webhook\",\n \"label\": \"Produção, esteira de crédito\",\n \"events\": [\n \"registry.document.assessed\",\n \"collection.completed\",\n \"collection.message.failed\"\n ],\n \"enabled\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://gyra-core.gyramais.com.br/v1/webhook/endpoints")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"url\": \"https://api.suaempresa.com/gyra/webhook\",\n \"label\": \"Produção, esteira de crédito\",\n \"events\": [\n \"registry.document.assessed\",\n \"collection.completed\",\n \"collection.message.failed\"\n ],\n \"enabled\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://gyra-core.gyramais.com.br/v1/webhook/endpoints")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"url\": \"https://api.suaempresa.com/gyra/webhook\",\n \"label\": \"Produção, esteira de crédito\",\n \"events\": [\n \"registry.document.assessed\",\n \"collection.completed\",\n \"collection.message.failed\"\n ],\n \"enabled\": true\n}"
response = http.request(request)
puts response.read_body{
"id": "6612a7f30000000000000091",
"url": "https://api.suaempresa.com/gyra/webhook",
"label": "Produção, esteira de crédito",
"events": [
"registry.document.assessed",
"collection.completed",
"collection.message.failed"
],
"enabled": true,
"secretHint": "…a91f4c",
"secret": "whsec_4f1c9e2b7a6d3058c1e2f4a9b8d7c6e5f0a1b2c3d4e5f60718293a4b5ca91f4c",
"createdAt": "2026-09-05T18:40:00.000Z",
"organizationId": "6612a7f30000000000000009",
"consecutiveFailures": 0,
"lastDeliveryStatus": null,
"lastDeliveryError": null,
"lastDeliveryAt": null,
"updatedAt": "2026-09-06T10:12:00.000Z"
}{
"code": 400,
"message": "url must be a URL address"
}{
"code": 401,
"message": "Token de acesso inválido."
}{
"code": 403,
"message": "Você não tem permissão para acessar este recurso."
}{
"code": 404,
"message": "Assinatura de webhook não encontrada."
}{
"code": 500,
"message": "Internal server error"
}{
"code": 502,
"message": "Não foi possível salvar a assinatura."
}Quando usar
Para assinar os eventos do módulo e parar de fazer polling.Lista de eventos vazia quer dizer todos
Quem está começando não sabe de quais precisa, e escolher antes de conhecer produz assinatura errada e evento perdido em silêncio.O segredo aparece uma vez
Ele volta em claro só nesta resposta, na criação e na rotação. Confira a assinatura comHMAC_SHA256(segredo, "<X-Gyra-Timestamp>.<corpo cru>") e recuse o que estiver fora de uma janela de cinco minutos.
Authorizations
Enter JWT token
Body
URL publica, http ou https, com dominio.
"https://api.suaempresa.com/gyra/webhook"
Ausente cria; presente atualiza.
Como a assinatura aparece na tela. Na atualizacao, omitir mantem o atual; string vazia limpa.
80Vazio ou ausente quer dizer TODOS os eventos, inclusive os de relatorio e credito. Sem repeticao.
Religar zera o contador de falhas seguidas.
Valor enviado no cabecalho api-key, so nos eventos de relatorio e credito (esses nao usam a assinatura HMAC).
Response
Assinatura salva. Na criacao e na rotacao, inclui o secret em claro (unica vez).
O segredo em claro, no formato whsec_ seguido de 64 caracteres hexadecimais. SO VEM AQUI, na criacao e na rotacao. Guarde no seu cofre.
Presente so quando os eventos de relatorio e credito nao foram salvos; diz o motivo.

