# GitHub webhook

Source: https://immiscible.fly.dev/docs/api/post-hooks-github-wid

`POST /hooks/github/:wid`

Pull request events, verified against `x-hub-signature-256`. A merged PR marks linked tasks `accepted`; one closed without merging marks them `rejected`.

## Authentication

Issuer signature. No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read. GitHub's `x-hub-signature-256` header, checked with the secret saved when the GitHub integration was connected.

## Path parameters

- `wid` (string, required): Workspace id

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/hooks/github/$IMMISCIBLE_WORKSPACE" \
  -H "x-hub-signature-256: $SIGNATURE"
```

Node:

```ts
// signature: computed over the raw body, see the authentication note above
const res = await fetch('https://immiscible.fly.dev/hooks/github/$IMMISCIBLE_WORKSPACE', {
  method: 'POST',
  headers: {
    'x-hub-signature-256': signature,
  },
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import requests

# signature: computed over the raw body, see the authentication note above
res = requests.post(
    "https://immiscible.fly.dev/hooks/github/$IMMISCIBLE_WORKSPACE",
    headers={
        "x-hub-signature-256": signature,
    },
)
print(res.status_code, res.json())
```
