Skip to main content
Uses: CLI · Python · TypeScript
While you are building, you usually don’t have a public HTTPS endpoint for a destination. The live stream (GET /v1/triggers/subscribe) fills that gap: it sends you the account’s trigger events as they are captured, over one outbound connection.
The stream is for development, not production. It is unsigned, it carries no delivery guarantees, and its delivery field always reads "pending". Production delivery is a destination plus signature verification.

1. Watch events arrive

Create and enable a trigger first (step 2 of the webhook recipe), then open a stream filtered to it and make a change in the connected app.
listen prints one compact JSON line per event, so it pipes straight into jq:
Filter by --trigger, --slug (a trigger type) or --app. Stop with Ctrl-C (from CLI 0.23.0; it prints a summary line and exits 0).

2. Rehearse a signed delivery on localhost

--forward POSTs every streamed event to a local URL in the same envelope a real delivery uses. Add --sign-with and each POST carries a genuine X-Engini-Signature, so the verification code you will deploy is exactly the code you are testing - no tunnel needed.
  • The secret only has to match between the two terminals - it does not need to be a real destination secret. ENGINI_TRIGGER_SIGNING_SECRET works in place of --sign-with.
  • Without a secret, the forwarded POSTs are unsigned, and a correct receiver rejects them.
  • The forwarded body always has attempt: 1, and trigger_slug is usually null - check the slug against your trigger id, not the body, if your receiver branches on it.
  • A failed forward never stops the stream. When the stream ends on its own with any failed forwards, listen exits 1, and the summary line {"events": n, "forwarded": n, "failed": n} shows how many.

3. Know how a stream ends

Pass --no-resume (CLI), auto_resume=False (Python) or autoResume: false (TypeScript) to handle the one-hour cut yourself.

When you’re ready for production

Register a real destination and deploy the same receiver behind HTTPS: Receive trigger events on a webhook. The verification you rehearsed here is unchanged.