exa-webhooks-events

Installation
SKILL.md

Exa Monitor Webhook Processing

Overview

Receive Exa Monitor events through verified signatures, replay resistance, deduplication, and fast acknowledgment. Treat credentials, queries, retrieved content, generated output, spend, and destructive state as separately governed boundaries.

Prerequisites

  • The target repository, environment, Exa team, product surface, and accountable owner.
  • The workload's data classification, latency and freshness promise, cost ceiling, and retention policy.
  • Current first-party documentation plus credentials only for a narrowly approved live check.

Current Contract

Monitors schedule recurring searches, deduplicate prior results, and deliver to an HTTPS public webhook. The one-time webhookSecret is returned only when a Monitor is created. Exa-Signature carries timestamp and v1 values for HMAC-SHA256 verification over the signed payload; redirects are not followed.

Authentication

For normal REST work, inject EXA_API_KEY from an approved server-side secret manager and send it only as Authorization: Bearer to the configured first-party Exa API host. Team Management service keys, hosted MCP OAuth or enterprise managed authorization, and payment-protocol calls are separate trust models. Never print, commit, place in a URL, or expose a credential to an untrusted client.

Installs
24
GitHub Stars
2.7K
First Seen
Feb 18, 2026
exa-webhooks-events — jeremylongshore/tons-of-skills-marketplace