Skip to content
colis

Use case

Change requests in your own tools

Every request for changes arrives signed on your route, with the client’s comment, ready to become a ticket.

app/api/colis/route.ts
import { verifyWebhook } from '@colis/protocol'

export async function POST(request: Request) {
  const body = await request.text()
  const result = await verifyWebhook(process.env.DROP_WEBHOOK_SECRET!, request.headers, body)
  if (!result.valid) return new Response(null, { status: 401 })

  const event = JSON.parse(body)
  if (event.type === 'parcel.changes_requested') {
    await createIssue({                       // your tracker
      title: `Corrections : ${event.data.filename}`,
      body: event.data.comment,
      reference: event.data.code,
    })
  }

  return new Response(null, { status: 204 })
}

The situation

What is actually going on.

The problem

Client feedback gets lost between email, chat and calls. The one that matters, “the logo as SVG, and a lighter background”, has to end up in your tracker.

What colis does about it

Point DROP_WEBHOOK_URL at a route of yours. verifyWebhook from @colis/protocol checks the Standard Webhooks signature (HMAC-SHA256) with the same code the deployment signs with. On parcel.changes_requested, data.comment carries what the client wrote: open the ticket, and link the parcel by its code.

Worth watching

The things that are easy to get wrong.

Read the raw body

The signature covers the bytes received: request.text() before any JSON.parse.

Five minutes of tolerance

A timestamp more than five minutes off is refused, so an old delivery cannot be replayed.

No secret in the event

data never holds the password, its hash, or the sender’s token.

Packages@colis/protocol

Send it. They sign off. You know.

Your storage, a delivery page under your name, a webhook at every step. Nothing hosted by someone else.