Diska
API

Webhooks

Outbound (call event) and inbound webhooks supported by Diska.

Diska sends outbound webhooks to your systems when events happen (completed calls, bookings) and receives external webhooks for asynchronous events.

Outbound webhooks (call events)

Register endpoints via the API Channel with the webhooks:manage scope:

POST /v1/webhook-endpoints
Authorization: Bearer dsk_…
{
  "url": "https://your-system.com/hooks/diska",
  "events": ["call.completed"]
}

The response includes the signing secret (dskw_…) — store it: it is shown only once.

Available events

EventWhen it firesPayload
call.completedA call finishes successfully and post-call processing completes. Failed, cancelled or abandoned calls do not fire this event.Full transcript, extracted data, evaluations, sentiment, executed actions, call_id (usable with GET /v1/calls/{call_id}).
booking.createdA booking is created during a call.booking_id, session_id.

Verifying the signature

Every delivery includes the headers:

X-Diska-Event:      call.completed
X-Diska-Delivery:   <unique delivery uuid>
X-Diska-Timestamp:  <unix seconds>
X-Diska-Signature:  sha256=<hex>

The signature is an HMAC-SHA256 of the text {timestamp}.{request body} with the endpoint's secret:

import hashlib, hmac

def is_valid(secret: str, timestamp: str, body: bytes, signature: str) -> bool:
    expected = hmac.new(secret.encode(), f"{timestamp}.".encode() + body, hashlib.sha256).hexdigest()
    return hmac.compare_digest(f"sha256={expected}", signature)

Reject requests whose timestamp is older than 5 minutes to prevent replay.

Delivery and failures

  • Respond 2xx quickly (ideally: enqueue and process later). Any other response counts as a failure.
  • Each delivery is attempted up to 3 times with backoff; 4xx errors (except 408/429) are not retried.
  • After 20 consecutive failures the endpoint is disabled automatically (disabled_reason explains). Fix it and re-enable with PATCH /v1/webhook-endpoints/{id} {"active": true}.
  • Use POST /v1/webhook-endpoints/{id}/test to receive a signed ping and validate your implementation.
  • Delivery is best-effort: for reconciliation, GET /v1/calls remains the source of truth.

Inbound webhooks

SMS inbound

POST /api/v1/webhooks/sms/inbound

Receives SMS messages from the provider Ombala. The body varies depending on the provider payload. The API validates the origin, associates the message with a session if one exists and can advance the flow when configured to await a response.

Configure the webhook URL in the provider dashboard:

https://api.diska.ai/api/v1/webhooks/sms/inbound

Security: validate provider signatures or tokens when available, use HTTPS and restrict source IPs if the provider supports it.

Future

Additional outbound events (call.failed, realtime call states) and inbound webhooks for Cal.com and Twilio are planned.

Copyright © 2026