Webhooks can cover an account or one study. Subscribe to
interview.completed, study.completed, report.ready, study.paused, study.resumed, or study.stopped. The three lifecycle events currently cover public API pause, resume, and stop calls. create_webhook returns an HMAC signing secret once; rotate_webhook_secret returns the replacement once. Store it securely and never repeat it in logs or ordinary chat output. List and get responses never include a secret.
Use test_webhook to verify the destination and list_webhook_deliveries to inspect recent attempts. The test event contains no participant or study data. Delivery history contains status and coarse errors, not request bodies.
Creating a webhook changes an external integration and should require user confirmation. If a temporary webhook is created for testing, delete it before finishing.
