job.succeeded, job.partial, and job.failed events so you do not need to poll every job. job.partial contains the ordered per-image successes and failures from a batch.
Select the environment
Choose Production, Staging or Sandbox when creating a destination. Each destination receives events only from its own environment. Staging events havelivemode: true and is_staging: true; they are sent only to staging destinations. Synthetic test events preserve the destination’s environment. Events recorded before staging was introduced may omit is_staging; treat its absence as false.
Verify every request
Compute HMAC-SHA256 over the exact string
<timestamp>.<raw request body> with the webhook endpoint secret. Compare signatures in constant time and reject timestamps older than five minutes.
Respond and deduplicate
Return any2xx only after durably recording or processing the event. CarHub retries non-2xx deliveries. Use Carhub-Event-Id as your idempotency key because retries represent the same event.
The endpoint secret is returned only when the destination is created. Store it as securely as your API key.