How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Bem Webhooks API

bem POSTs a JSON event to your configured webhook URL each time a subscribed function call, workflow output, or collection-processing job fires. This section is the reference for those deliveries: the payload shape per event type, plus the endpoints you use to manage the signing secret.Every variant shares the same envelope — function/workflow IDs, timestamps, the inbound email that triggered the call, and so on — and adds a payload field that depends on the function type. The `eventType` field on the body is the discriminator: dispatch on it to select which payload shape to expect. SDKs generated from this spec expose a `webhooks.unwrap()` helper that performs the dispatch and returns a typed event.## Payloads| `eventType` | Payload | Schema || --- | --- | --- || `extract` | [Extract event](/api/v3/webhooks/events/extract) | `ExtractEvent` || `classify` | [Classify event](/api/v3/webhooks/events/classify) | `ClassifyEvent` || `parse` | [Parse event](/api/v3/webhooks/events/parse) | `ParseEvent` || `split_collection` | [Split collection event](/api/v3/webhooks/events/split-collection) | `SplitCollectionEvent` || `split_item` | [Split item event](/api/v3/webhooks/events/split-item) | `SplitItemEvent` || `join` | [Join event](/api/v3/webhooks/events/join) | `JoinEvent` || `enrich` | [Enrich event](/api/v3/webhooks/events/enrich) | `EnrichEvent` || `payload_shaping` | [Payload shaping event](/api/v3/webhooks/events/payload-shaping) | `PayloadShapingEvent` || `send` | [Send event](/api/v3/webhooks/events/send) | `SendEvent` || `evaluation` | [Evaluation event](/api/v3/webhooks/events/evaluation) | `EvaluationEvent` || `collection_processing` | [Collection processing event](/api/v3/webhooks/events/collection-processing) | `collectionProcessingEvent` || `error` | [Error event](/api/v3/webhooks/events/error) | `ErrorEvent` |## Signing secretEvery delivery includes a `bem-signature` header in the format `t={unix_timestamp},v1={hex_hmac_sha256}`. The signature covers `{timestamp}.{raw_request_body}` and is computed with HMAC-SHA256 using the active signing secret for your environment.To verify a payload:1. Parse `bem-signature: t={timestamp},v1={signature}`.2. Construct the signed string: `{timestamp}.{raw_request_body}`.3. Compute HMAC-SHA256 of that string using your secret.4. Reject the request if the hex digest doesn't match `v1`, or if the timestamp is more than a few minutes old.Manage the secret with these endpoints:- [**Generate a signing secret**](/api/v3/webhooks/secret/generate-secret) — `POST /v3/webhook-secret`. Returns the new secret in full exactly once.- [**Get the signing secret**](/api/v3/webhooks/secret/get-secret) — `GET /v3/webhook-secret`. Returns the active secret.- [**Revoke the signing secret**](/api/v3/webhooks/secret/revoke-secret) — `DELETE /v3/webhook-secret`. Webhook deliveries continue but are unsigned until a new secret is generated.For zero-downtime rotation, briefly accept both the old and new secret in your verification logic before revoking the old one.## Retriesbem treats any non-2XX response (or a transport failure) as a delivery error and retries with exponential backoff. Return a 2XX as soon as you have durably queued the payload — do not block on downstream work.

Bem Webhooks API is one of 22 APIs that Bem publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Webhook. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 3 operations across 1 path, and defines 22 schemas. It is described by OpenAPI 3.2.0, at version 1.0.0.

Requests are made against 2 base URLs: https://api.bem.ai, https://api.eu1.bem.ai.

3 operations 1 paths 22 schemas 1 DELETE1 GET1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.0
Base URL
https://api.bem.ai
Authentication
API Key, API Key
Resource Areas
1

Authentication & Security 2

Bem Webhooks API declares 2 security schemes for authenticating requests. An API key is passed in the header as x-api-key (API_Key). An API key is passed in the header as x-api-key (API Key). By default, every request must be authenticated.

  • API_Key — Authenticate using API Key in request header
  • API Key — Authenticate using API Key in request header

Paths & Operations 3

Across 1 path, the API surfaces 3 operations — 1 DELETE, 1 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Webhooks 3

bem POSTs a JSON event to your configured webhook URL each time a subscribed function call, workflow output, or collection-processing job fires.

GET
/v3/webhook-secret
Get Webhook Secret
v3-get-webhook-secret → 200
POST
/v3/webhook-secret
Generate Webhook Secret
v3-generate-webhook-secret → 200
DELETE
/v3/webhook-secret
Revoke Webhook Secret
v3-revoke-webhook-secret → 200

Schemas 22

The contract defines 22 schemas that model the data the API accepts and returns. The most detailed are ExtractEvent (27 properties), ParseEvent (27 properties), JoinEvent (22 properties), SendEvent (21 properties). Each schema is shown below with its type and property counts.

SplitItemEvent
object
18 properties 5 required
SplitCollectionEvent
object
18 properties 7 required
SendEventS3Output
object
Metadata returned when a Send function delivers to an S3 bucket.
2 properties 2 required
EnrichEvent
object
16 properties 5 required
WebhookSecret
object
Webhook signing secret used to verify bem-signature headers on delivered webhooks.
1 property 1 required
EvaluationEvent
object
Emitted when a function-accuracy evaluation completes for a transformation. Evaluations are scheduled by POST /v3/eval and run asynchronously; this event repor…
20 properties 8 required
SendDeliveryStatus
string
Outcome of a Send function's delivery attempt.
SendEvent
object
21 properties 6 required
AnyType
InputType
string
The input type of the content you're sending for transformation.
JoinEventItem
object
4 properties 3 required
JoinEvent
object
22 properties 8 required
SendEventGoogleDriveOutput
object
Metadata returned when a Send function delivers to Google Drive.
2 properties 2 required
ParseEvent
object
Emitted when a parse function completes. Reuses the extract event shape on the wire — both wrap a Transformation and downstream consumers care about the same t…
27 properties 7 required
SendDestinationType
string
Destination type for a Send function.
ClassifyEvent
object
17 properties 5 required
EventInboundEmail
object
4 properties 3 required
ErrorEvent
object
17 properties 5 required
SendEventWebhookOutput
object
Metadata returned when a Send function delivers to a webhook.
2 properties 2 required
PayloadShapingEvent
object
Emitted by payloadshaping functions, which restructure JSON payloads using JMESPath expressions configured on the function. The shaped result is carried in tra…
16 properties 5 required
collectionProcessingEvent
object
14 properties 7 required
ExtractEvent
object
V3 event variants that do not exist in the shared Event union. ExtractEvent and ClassifyEvent are emitted only by V3-era function types (extract and classify).…
27 properties 7 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

bem-webhooks-api-openapi.yml Raw ↑

Other APIs Bem publishes across the network.

Bem Buckets API
Bem Calls API
Bem Collections API
Bem Connectors API
Bem Entity Bulk Seed API
Bem Entity Curation API
Bem Entity Synonyms API
Bem Entity Type Reviewers API
Bem Entity Types API
Bem Errors API
Bem Feedback API
Bem Function Accuracy API
Where this information came from

This is an independent, third-party profile of Bem Webhooks API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.