Vue d’ensemble

Les webhooks vous permettent de recevoir des événements KennHosting sur votre serveur dès qu’un changement d’état se produit (activation VPS, domaine enregistré, wallet crédité…). Scope requis : reseller:webhooks

Configurer l’URL webhook

PUT /api/v1/reseller/webhook
curl -X PUT "https://kennhosting.com/api/v1/reseller/webhook" \
  -H "Authorization: Bearer kh_live_YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://votre-site.cm/kh-webhook",
    "secret": "votre_secret_hmac"
  }'
Réponse :
{
  "success": true,
  "data": {
    "url": "https://votre-site.cm/kh-webhook",
    "has_secret": true
  }
}

Consulter la configuration

GET /api/v1/reseller/webhook
{
  "success": true,
  "data": {
    "url": "https://votre-site.cm/kh-webhook",
    "has_secret": true
  }
}
Le secret n’est jamais retourné en clair dans les réponses — seul has_secret: true/false est indiqué.

Tester la connexion

POST /api/v1/reseller/webhook/test
Envoie un événement fictif signé à votre URL configurée.
{
  "success": true,
  "data": {
    "url": "https://votre-site.cm/kh-webhook",
    "status_code": 200,
    "delivered": true,
    "error": null
  }
}

Signature des événements

Chaque webhook est signé avec HMAC-SHA256 :
X-KennHosting-Signature: sha256=HMAC(body, secret)
Vérification en PHP :
$payload = file_get_contents('php://input');
$signature = $_SERVER['HTTP_X_KENNHOSTING_SIGNATURE'] ?? '';

$expected = 'sha256=' . hash_hmac('sha256', $payload, 'votre_secret_hmac');

if (!hash_equals($expected, $signature)) {
    http_response_code(401);
    exit('Signature invalide');
}

$event = json_decode($payload, true);
// Traiter $event['event']

Événements disponibles

ÉvénementDescription
hosting.createdCompte d’hébergement créé
domain.registeredDomaine enregistré
vps.provisioningVPS en cours de création
vps.activatedVPS opérationnel
email.provisioningEmail Pro en cours de création
email.activatedEmail Pro actif
wallet.debitedDébit wallet
wallet.creditedCrédit wallet

Format d’un événement

{
  "event": "vps.activated",
  "sandbox": false,
  "timestamp": "2026-06-12T19:00:00Z",
  "data": {
    "client_id": 1,
    "order_uuid": "b1912d95-...",
    "server_id": 12345,
    "ipv4": "1.2.3.4",
    "status": "running"
  }
}
Les événements sandbox incluent toujours "sandbox": true.