Skip to content
Registry StackDocsDevelopment (unreleased)

Accept a signed source synchronization hint

POST
/events/sources/{source_id}
curl --request POST \
--url https://casework.example.test/events/sources/example \
--header 'Content-Type: application/cloudevents+json' \
--header 'X-Registry-Signature: <X-Registry-Signature>' \
--header 'ce-dataschema: https://example.com' \
--header 'ce-id: 2489E9AD-2EE2-8E00-8EC9-32D5F69181C0' \
--header 'ce-source: https://example.com' \
--header 'ce-specversion: 1.0' \
--header 'ce-time: 2026-04-15T12:00:00Z' \
--header 'ce-type: example' \
--header 'idempotency-key: example' \
--header 'x-registry-delivery-attempt: example' \
--header 'x-registry-delivery-time: 2026-04-15T12:00:00Z' \
--header 'x-registry-event-generation: example' \
--header 'x-registry-signature: example' \
--data '{}'

Authentication uses the configured BReg webhook signature and timestamp headers. The raw body is bounded to 1 MiB and grants no authority or display content.

source_id
required
string

Configured source identifier.

traceparent
string

Optional W3C trace context continued in the response.

ce-specversion
required
string
Allowed value: 1.0

CloudEvents version; exactly 1.0.

ce-id
required
string format: uuid

Event UUID.

ce-source
required
string format: uri
>= 1 characters <= 512 characters

Configured exact event source URI.

ce-type
required
string
>= 1 characters <= 512 characters

Configured exact request-lifecycle event type.

ce-time
required
string format: date-time

Event timestamp.

ce-dataschema
required
string format: uri
>= 1 characters <= 2048 characters

Configured event data schema URI.

x-registry-event-generation
required
string
<= 19 characters /^[1-9][0-9]{0,18}$/

Activated positive BReg source generation.

x-registry-delivery-attempt
required
string
<= 19 characters /^[1-9][0-9]{0,18}$/

Positive delivery attempt number.

x-registry-delivery-time
required
string format: date-time

Signed delivery timestamp.

idempotency-key
required
string
>= 71 characters <= 71 characters /^sha256:[0-9a-f]{64}$/

Signed delivery key derived from the exact event, delivery, generation, payload, and destination binding.

x-registry-signature
required
string
>= 46 characters <= 46 characters /^v1=[A-Za-z0-9_-]{43}$/

BReg Version 1 HMAC-SHA-256 signature over the exact request.

object
Examplegenerated
{}

Signature accepted; authoritative readback is scheduled.

traceparent
string

W3C trace context for the request and response.

Problem response: request.invalid, source.signature-invalid

Media typeapplication/problem+json
One of:
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: request.invalid
detail
required
Allowed value: The Casework request is invalid.
status
required
Allowed value: 400
title
required
Allowed value: Invalid request
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/request/invalid
Example
{
"code": "request.invalid",
"detail": "The Casework request is invalid.",
"status": 400,
"title": "Invalid request",
"type": "https://id.registrystack.org/problems/registry-casework/request/invalid"
}
traceparent
string

W3C trace context for the request and response.

Problem response: source.not-found

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: source.not-found
detail
required
Allowed value: The requested source is not registered.
status
required
Allowed value: 404
title
required
Allowed value: Source not found
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/source/not-found
Example
{
"code": "source.not-found",
"detail": "The requested source is not registered.",
"status": 404,
"title": "Source not found",
"type": "https://id.registrystack.org/problems/registry-casework/source/not-found"
}
traceparent
string

W3C trace context for the request and response.

Problem response: request.method-not-allowed

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: request.method-not-allowed
detail
required
Allowed value: This route does not accept that HTTP method.
status
required
Allowed value: 405
title
required
Allowed value: Method not allowed
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/request/method-not-allowed
Example
{
"code": "request.method-not-allowed",
"detail": "This route does not accept that HTTP method.",
"status": 405,
"title": "Method not allowed",
"type": "https://id.registrystack.org/problems/registry-casework/request/method-not-allowed"
}
traceparent
string

W3C trace context for the request and response.

Problem response: request.body-too-large

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: request.body-too-large
detail
required
Allowed value: The request body exceeds the one MiB limit.
status
required
Allowed value: 413
title
required
Allowed value: Request body too large
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/request/body-too-large
Example
{
"code": "request.body-too-large",
"detail": "The request body exceeds the one MiB limit.",
"status": 413,
"title": "Request body too large",
"type": "https://id.registrystack.org/problems/registry-casework/request/body-too-large"
}
traceparent
string

W3C trace context for the request and response.

Problem response: runtime.failure

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: runtime.failure
detail
required
Allowed value: Casework could not complete the request.
status
required
Allowed value: 500
title
required
Allowed value: Casework runtime failure
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/runtime/failure
Example
{
"code": "runtime.failure",
"detail": "Casework could not complete the request.",
"status": 500,
"title": "Casework runtime failure",
"type": "https://id.registrystack.org/problems/registry-casework/runtime/failure"
}
traceparent
string

W3C trace context for the request and response.

Problem response: source.bad-gateway

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: source.bad-gateway
detail
required
Allowed value: The source returned a response that does not match its registered contract.
status
required
Allowed value: 502
title
required
Allowed value: Invalid source response
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/source/bad-gateway
Example
{
"code": "source.bad-gateway",
"detail": "The source returned a response that does not match its registered contract.",
"status": 502,
"title": "Invalid source response",
"type": "https://id.registrystack.org/problems/registry-casework/source/bad-gateway"
}
traceparent
string

W3C trace context for the request and response.

Problem response: service.unavailable, work-item.source-unavailable

Media typeapplication/problem+json
One of:
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: service.unavailable
detail
required
Allowed value: Casework storage is unavailable. Try again after the service recovers.
status
required
Allowed value: 503
title
required
Allowed value: Casework service unavailable
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/service/unavailable
Example
{
"code": "service.unavailable",
"detail": "Casework storage is unavailable. Try again after the service recovers.",
"status": 503,
"title": "Casework service unavailable",
"type": "https://id.registrystack.org/problems/registry-casework/service/unavailable"
}
Retry-After
integer

Seconds before retrying the unavailable dependency.

traceparent
string

W3C trace context for the request and response.