Subscribe to anime.created, anime.updated, episode.released and episode.updated in the Developer Portal or /v1/developer/applications/{applicationId}/webhooks. Management requires human webhooks.read/webhooks.write scopes and application ownership. API keys cannot manage webhooks. Sign in again to request newly added scopes.
Receiver URLs must use HTTPS, public DNS and port 443, without credentials, queries or fragments. Every connection resolves and validates all addresses, then connects to the validated IP while keeping normal TLS hostname/certificate validation. Proxies and redirects are disabled. Use an isolated public egress policy in production.
Deliveries are at least once with stable event and delivery IDs. A 2xx response acknowledges receipt. Timeouts, network errors, 408/425/429 and 5xx retry up to eight attempts with backoff and bounded Retry-After. Redirects and other 4xx fail permanently. Up to three manual retry cycles are available. Ordering is not guaranteed; compare data.revision before applying updates.
Signing secrets are shown only on creation or rotation and stored with ASP.NET Data Protection. The signature is v1=<hex HMAC-SHA256> of UTF-8(secret), using ASCII(timestamp) + a dot + the raw body. Read Aniyori-Timestamp and Aniyori-Signature, compare in constant time and reject timestamps outside a five-minute window. Deduplicate the signed payload id durably before side effects.
New and re-enabled subscriptions start after the current committed publication, without backfilling history. Changes come from approved import/review publication handlers; direct SQL and legacy editors do not emit public events. Private user library changes are excluded. Rotation immediately changes new attempts; already claimed attempts may use the old secret version.
curl -X POST "https://api.aniyori.cz/v1/developer/applications/$APPLICATION_ID/webhooks" -H "Authorization: Bearer $USER_ACCESS_TOKEN" -H "Content-Type: application/json" -d '{"name":"Receiver","url":"https://example.com/webhooks/aniyori","events":["anime.updated"]}'