Feature × Audience

How does government use webhooks for audit trails?

Plugsky webhooks push signed events to an HTTPS endpoint you control, so government teams can automate instead of poll. Deliveries are HMAC-SHA256 signed and cover nine event types, including quota.warning, key.rotated, usage.threshold, invoice.paid, model.deprecated and audit.alert. Return 2xx quickly, process asynchronously, and make handlers idempotent because delivery is at-least-once.

Key facts

TransportHTTPS endpoint you host
SignatureHMAC-SHA256 signed deliveries
Event typesquota.warning, quota.exceeded, key.rotated, model.deprecated, usage.threshold, invoice.paid, audit.alert, batch.completed, fine_tuning.completed
ConfigurationDashboard → Webhooks
Response handlingReturn 2xx quickly; process asynchronously
Delivery semanticsAt-least-once; design idempotent handlers
SIEM exportAudit events can flow to Splunk, Sentinel, QRadar and Chronicle
Status noteDeliveries are live; events tied to coming-soon endpoints depend on the roadmap

TL;DR

  • Signed HTTPS deliveries replace polling for platform events.
  • HMAC-SHA256 verification happens before any payload is parsed.
  • Nine event types cover quotas, keys, models, usage, invoicing and audit.
  • Send audit.alert and key.rotated events into the agency logging platform, keep an append-only record, and treat model.deprecated as a migration trigger for citizen-facing services.
  • Handlers must be idempotent because delivery is at-least-once.

How it works, step by step

  1. List the platform events your public-sector workflows should react to.
  2. Stand up an HTTPS endpoint you control and register it in Dashboard → Webhooks.
  3. Verify the HMAC-SHA256 signature over the raw body before parsing.
  4. Return 2xx quickly and enqueue the event for asynchronous processing.
  5. Make handlers idempotent so retries and duplicates are safe.
  6. Add a dead-letter queue and alert when deliveries fail repeatedly.
  7. Replay test events against a staging endpoint before production cut-over.
1List the platformevents yourpublic-sector2Stand up an HTTPSendpoint youcontrol and3Verify theHMAC-SHA256signature over the4Return 2xx quicklyand enqueue theevent for5Make handlersidempotent soretries and6Add a dead-letterqueue and alertwhen deliveries

Try it yourself

Open the AI data residency checklist →

Why government teams should react to events

Government teams process citizen records, case files and procurement documents under sovereignty rules. Procurement asks for controlled processing, auditability and a clear answer on where data — and model weights — actually live.

Auditability is the requirement: agencies need evidence of key rotation, quota events and model changes in a form their oversight processes can consume.

How Plugsky webhooks work

Register an HTTPS endpoint in Dashboard → Webhooks. Plugsky delivers signed events to the endpoint you host; every delivery is HMAC-SHA256 signed, so verify the signature over the raw body before parsing. Nine event types are documented: quota.warning, quota.exceeded, key.rotated, model.deprecated, usage.threshold, invoice.paid, audit.alert, batch.completed and fine_tuning.completed. Return a 2xx quickly and process the event asynchronously; deliveries are at-least-once, so handlers must tolerate duplicates. Events tied to endpoints the docs still list as coming soon depend on the roadmap, so confirm availability before building on them.

Security and reliability patterns

Patterns that keep the integration small and defensible:

  • Verify signatures before parsing and keep an append-only record of deliveries.
  • Route audit.alert and key.rotated to the agency logging platform.
  • Minimise payload content and fetch detail under existing access controls.
  • In air-gapped environments, use internal event pipelines instead of external webhooks.

Putting webhooks to work

Send audit.alert and key.rotated events into the agency logging platform, keep an append-only record, and treat model.deprecated as a migration trigger for citizen-facing services.

Start from the events that protect revenue and access: quota.warning, quota.exceeded, key.rotated and audit.alert. Add model.deprecated and usage.threshold as you automate more. The integration surface is small — one endpoint, one signature check, one idempotent handler — and the request path stays OpenAI-compatible, so nothing about your API calls changes. Self-serve plans are flat monthly with unlimited fair-use usage and no per-token billing; current plans are on the pricing page. Prototype on the free plan and use the 14-day full-access trial when you need larger models.

Honest comparison

FactorPlugsky webhooksPolling the APIBuilding an event bus in-house
Delivery modelPush, HTTPS, HMAC-SHA256 signedPull on a scheduleYou design and operate it
Event coverageNine platform event typesWhatever you remember to queryOnly what you instrument
Ops overheadLow — endpoint plus handlerLow but laggyHigh — queues, retries, on-call
Reaction timeSeconds after the eventNext poll intervalDepends on your pipeline
Audit pathaudit.alert plus SIEM exportManual log queriesYou build the trail
Time to integrateHoursHoursWeeks

Frequently asked questions

Do webhooks work in an air-gapped environment?

No external webhook deliveries are possible without egress. In air-gapped deployments, route the same event signals through your internal event bus and log pipeline.

Can we keep using the OpenAI SDK?

Yes. The request path stays OpenAI-compatible, so you change the base URL and model names and keep your existing SDK code, prompts and evaluations.

How do I verify a webhook signature?

Compute an HMAC-SHA256 over the raw request body with your signing secret and compare it to the signature header in constant time before parsing the payload.

What happens if our endpoint is down?

Delivery is at-least-once and retried, so events may arrive again after recovery. Keep a dead-letter queue, alert on repeated failures, and make handlers idempotent.

Can deliveries be duplicated or reordered?

Treat delivery as at-least-once: deduplicate by event identity and process per entity where order matters rather than assuming a strict global sequence.

What should the endpoint return?

Return a 2xx quickly before doing the work, then process the event asynchronously so a slow downstream job cannot cause retries.

How is pricing structured?

Webhooks are part of the platform: self-serve plans are flat monthly with unlimited fair-use usage and no per-token billing. See the live pricing page for current plans.

Is there a free plan?

Yes — the free plan includes plugsky-micro and plugsky-lite with no credit card, and a 14-day full-access trial covers larger models.