expense.updated
Sent when an expense is replaced or its file is swapped. Each event is attempted up to 3 times: the first delivery, then retries after 10 s and 100 s; only a 2xx response counts as success. The request times out after 10 seconds.
Header Parameters
Lowercase hex HMAC-SHA256 of the raw request body, keyed with the webhook's signing secret (whsec_…). Recompute it over the exact bytes received and compare with a constant-time function before trusting the payload. No timestamp or event-id header is sent.
^[0-9a-f]{64}$Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
Example Requests
/expense.updatedexpense.created Webhook
Sent when an expense is created through the API or the app. Each event is attempted up to 3 times: the first delivery, then retries after 10 s and 100 s; only a 2xx response counts as success. The request times out after 10 seconds.
expense.deleted Webhook
Sent when an expense is deleted through the API or the app. The payload contains only the id of the deleted expense. Each event is attempted up to 3 times: the first delivery, then retries after 10 s and 100 s; only a 2xx response counts as success. The request times out after 10 seconds.