support
POST /v1/webhooks/inbound-email
Ingest a customer's support reply from the mail edge.
Санҷиши ҳаққоният
Ин нуқтаи поёни оммавӣ аст. Он ҳеҷ гуна маълумоти эътимоднок ва ҳеҷ гуна созмонро талаб намекунад — он ҳамон чизест, ки сайти маркетингӣ ва муҳаррикони ҷавоби сунъии худи мо мехонанд.
Ин нуқтаи поёнӣ ягон рақами мушаххаси созмонро талаб намекунад. Калиди шумо аллакай созмонеро, ки ба он тааллуқ дорад, муайян мекунад ва ҷавоб ба он маҳдуд карда мешавад.
Санҷидан
Ҳар чизро дар қаavски кунҷӣ бо қиматҳои худ ва ҷойи нигоҳдорандаи калидро бо калима аз панели идоракунии худ иваз кунед.
curl -X POST https://api.zinndigital.com/v1/webhooks/inbound-email \
-H "Content-Type: application/json" \
-d '{ "from": <string>, "message_id": <string> }'Воarid шудаед? Консоли API дар панели идоракунии шумо рақами мушаххаси ташкилоти воқеӣ ва калиди худро пур мекунад ва дархостро бар зидди API-и фаъол иҷро мекунад, то шумо посухи воқеиро бубинед. Ин нуқтаи ниҳоиро дар консоли API кушоед
Тафсилот
Unauthenticated by design — the caller is a Cloudflare Email Routing Worker with no Zinn® credential, so an HMAC over "<timestamp>\n<body>" in X-Zinn-Signature is the authentication. The timestamp is inside the signed material and its skew is bounded, so a captured request cannot be replayed later. This is the inbound half of support email. Before it existed the platform sent notifications from an address that accepted mail and discarded it: a customer replied, nothing happened, and neither they nor the waiting staff member was told. The ticket is resolved from a signed token inside the Message-ID we set on the outbound notification — nothing in the body, the From address or any other header selects a tenant, because all of those are chosen by whoever sent the mail. Redelivery is the normal case, not the exception: email is at-least-once and a lost response guarantees a retry, so a message already filed answers 200 with duplicate: true rather than appending a second copy. ⛔ Unlike the gateway webhooks, a message that cannot be routed is answered 422, not 200. A 2xx tells the Worker to accept the mail, and an accepted message that reaches no ticket is the exact defect this endpoint exists to remove; 422 makes the Worker reject it so the sender's own mail server bounces it back to the customer.
Параметрҳо
| Ном | Намуд | Талаб карда мешавад | Ин чӣ аст |
|---|---|---|---|
X-Zinn-Timestamp (header) | string | Бале | Unix seconds. Inside the signed material; skew-bounded to five minutes. |
X-Zinn-Signature (header) | string | Бале | sha256=<hex> HMAC over "<timestamp>\n<body>". |
Ҷисми дархост
| Ном | Намуд | Талаб карда мешавад | Ин чӣ аст |
|---|---|---|---|
from | string | Бале | The envelope sender. Forgeable, and treated as such — it is checked against the ticket's org and the answer becomes a flag, never a permission. |
to | string | Не | — |
message_id | string | Бале | The message's own Message-ID. Stored, and unique, so a redelivery cannot append twice. |
in_reply_to | string | Не | Carries the signed ticket token when the customer replied to one of our notifications. |
references | string | Не | The full thread chain. Searched as well as in_reply_to, because a reply to the third message in a thread puts our id here and not there. |
subject | string | Не | — |
text | string | Не | The message body. Quoted history is trimmed engine-side and the result is length-bounded. |
Ҷавоб
| Ном | Намуд | Талаб карда мешавад | Ин чӣ аст |
|---|---|---|---|
ticket_id | string | Бале | — |
duplicate | boolean | Бале | This exact message had already been filed — a success, not an error. |
sender_verified | boolean | Бале | Whether the sender is a known address on the ticket's org. false still files the message, flagged for staff. |
reopened | boolean | Бале | Whether filing it moved a solved ticket back to open. |
Хатоҳое, ки ин нуқтаи ниҳоӣ метавонад баргардонад
400 · 422 · 503