Webhooks
Diska sends outbound webhooks to your systems when events happen (completed calls, bookings) and receives external webhooks for asynchronous events.
Outbound webhooks (call events)
Register endpoints via the API Channel with the webhooks:manage scope:
POST /v1/webhook-endpoints
Authorization: Bearer dsk_…
{
"url": "https://your-system.com/hooks/diska",
"events": ["call.completed"]
}
The response includes the signing secret (dskw_…) — store it: it is shown only once.
Available events
| Event | When it fires | Payload |
|---|---|---|
call.completed | A call finishes successfully and post-call processing completes. Failed, cancelled or abandoned calls do not fire this event. | Full transcript, extracted data, evaluations, sentiment, executed actions, call_id (usable with GET /v1/calls/{call_id}). |
booking.created | A booking is created during a call. | booking_id, session_id. |
Verifying the signature
Every delivery includes the headers:
X-Diska-Event: call.completed
X-Diska-Delivery: <unique delivery uuid>
X-Diska-Timestamp: <unix seconds>
X-Diska-Signature: sha256=<hex>
The signature is an HMAC-SHA256 of the text {timestamp}.{request body} with the endpoint's secret:
import hashlib, hmac
def is_valid(secret: str, timestamp: str, body: bytes, signature: str) -> bool:
expected = hmac.new(secret.encode(), f"{timestamp}.".encode() + body, hashlib.sha256).hexdigest()
return hmac.compare_digest(f"sha256={expected}", signature)
Reject requests whose timestamp is older than 5 minutes to prevent replay.
Delivery and failures
- Respond
2xxquickly (ideally: enqueue and process later). Any other response counts as a failure. - Each delivery is attempted up to 3 times with backoff;
4xxerrors (except 408/429) are not retried. - After 20 consecutive failures the endpoint is disabled automatically (
disabled_reasonexplains). Fix it and re-enable withPATCH /v1/webhook-endpoints/{id}{"active": true}. - Use
POST /v1/webhook-endpoints/{id}/testto receive a signedpingand validate your implementation. - Delivery is best-effort: for reconciliation,
GET /v1/callsremains the source of truth.
Inbound webhooks
SMS inbound
POST /api/v1/webhooks/sms/inbound
Receives SMS messages from the provider Ombala. The body varies depending on the provider payload. The API validates the origin, associates the message with a session if one exists and can advance the flow when configured to await a response.
Configure the webhook URL in the provider dashboard:
https://api.diska.ai/api/v1/webhooks/sms/inbound
Security: validate provider signatures or tokens when available, use HTTPS and restrict source IPs if the provider supports it.
Future
Additional outbound events (call.failed, realtime call states) and inbound webhooks for Cal.com and Twilio are planned.

