Handle Alliedstar scan-result and order notifications
Receives Alliedstar asynchronous notifications. The signature travels in the body as `sign` and is verified against the open platform public key. Public endpoint; no session authentication.
Receives Alliedstar asynchronous notifications. The signature travels in the body as sign and is verified against the open platform public key. Public endpoint; no session authentication.
Response Body
application/json
curl -X POST "https://example.com/webhooks/alliedstar"{ "code": "string", "msg": "string"}Serve one outbound attachment to a messaging provider GET
Short-lived (15 minute) HMAC URL for providers that fetch media by URL (Messenger, Instagram, Twilio). The token is verified before any storage read. Public endpoint.
Receive Gmail mailbox change pushes POST
Google Cloud Pub/Sub push authenticated by an OIDC token for GuideLab's push service account. Requests one coalesced mailbox sync. Public endpoint.