> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vort-sourcing.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SANDBOX ONLY: queue a test webhook (optionally with a bad signature)

> Queues one delivery with a fixture payload (`job_external_id: cert-webhook`, a fresh
`run_id` that does not exist on GET /runs) to the webhook URL registered for the
partner. With `valid_signature: false` the delivery is signed with a deliberately
wrong secret, sent once and never retried; your endpoint must reject it. Answers
404 `not_found` in production. See [Test webhooks](/sandbox#test-webhooks).




## OpenAPI

````yaml /api-reference/openapi.yaml post /sandbox/webhooks/test
openapi: 3.1.0
info:
  title: Vort Partner API
  version: 1.0.0
  summary: Server-to-server API for ATS vendors embedding Vort candidate matching.
  description: >
    Guides: [Integration flow](/integration-flow). UI rules: [UI
    specification](/ui-specification). Notices: [Notices](/notices).


    - Every call is server-to-server. `vpk_` keys and `vot_` org tokens MUST NOT
    reach a browser.

    - Clients MUST ignore unknown response fields; additive changes within v1
    are non-breaking.

    - Notices with an unknown `code` MUST be rendered generically from `title` +
    `body`,
      styled by `severity`, placed by `slot`.
    - Rate limits are per partner (default 120/minute, 20,000/day); `429`
    carries `Retry-After`.

    - Sandbox ([Sandbox guide](/sandbox)): every sandbox response carries
    `x-vort-environment: sandbox`;
      names are masked, reveals are synthetic and free, `target_count` <= 20, 20 real runs
      per organization per 24 h, `cert-*` jobs run certification fixtures, and the
      sandbox-only headers `x-vort-sandbox-simulate` / `x-vort-sandbox-reveal-price` and
      route `POST /sandbox/webhooks/test` exist. None of these exist in production.
  contact:
    name: Vort partner support (always include the run_id)
  license:
    name: Proprietary
    identifier: LicenseRef-Vort-Proprietary
servers:
  - url: https://vort-partner-api.vercel.app/sandbox/v1
    description: Sandbox
security:
  - partnerKey: []
    orgToken: []
tags:
  - name: Activation
    description: Connect a customer organization by redeeming its one-time activation code.
  - name: Users
    description: Register the recruiters who act on runs (a field, never a credential).
  - name: Jobs
    description: Jobs the runs search for.
  - name: Runs
    description: Start runs and read their progress, notices and candidates.
  - name: Candidates
    description: Reveal candidate contact details (charges credits).
  - name: Decisions
    description: Report recruiter decisions and the notices shown (mandatory).
  - name: Sandbox
    description: >-
      Sandbox-only helpers (see the [Sandbox guide](/sandbox)). Not present in
      production (404).
  - name: Webhooks
    description: >-
      Events Vort posts to your registered HTTPS endpoint, signed with
      `x-vort-signature`.
paths:
  /sandbox/webhooks/test:
    post:
      tags:
        - Sandbox
      summary: 'SANDBOX ONLY: queue a test webhook (optionally with a bad signature)'
      description: >
        Queues one delivery with a fixture payload (`job_external_id:
        cert-webhook`, a fresh

        `run_id` that does not exist on GET /runs) to the webhook URL registered
        for the

        partner. With `valid_signature: false` the delivery is signed with a
        deliberately

        wrong secret, sent once and never retried; your endpoint must reject it.
        Answers

        404 `not_found` in production. See [Test
        webhooks](/sandbox#test-webhooks).
      operationId: sandboxTestWebhook
      parameters:
        - $ref: '#/components/parameters/Lang'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - event
              properties:
                event:
                  type: string
                  enum:
                    - run_completed
                    - run_failed
                    - candidate_revealed
                valid_signature:
                  type: boolean
                  default: true
            example:
              event: run_completed
              valid_signature: false
      responses:
        '202':
          description: Queued.
          headers:
            x-vort-environment:
              description: Always `sandbox` on sandbox responses.
              schema:
                type: string
                const: sandbox
          content:
            application/json:
              schema:
                type: object
                required:
                  - event_id
                properties:
                  event_id:
                    type: string
                    format: uuid
                    description: >-
                      The `event_id` the delivery will carry (also header
                      `x-vort-event-id`).
                  event:
                    type: string
                  run_id:
                    type: string
                    format: uuid
                  valid_signature:
                    type: boolean
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '409':
          description: '`webhook_not_configured` (no webhook registered for the partner)'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: '`invalid_request`'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  parameters:
    Lang:
      name: x-vort-lang
      in: header
      required: false
      description: Language of notices and messages. Defaults to the partner default.
      schema:
        type: string
        enum:
          - he
          - en
  responses:
    Unauthorized:
      description: '`invalid_partner_key` or `invalid_org_token`'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: invalid_org_token
            message: The organization token is not valid.
    Forbidden:
      description: '`partner_disabled` or `organization_disabled`'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error: organization_disabled
            message: This organization's Vort connection is disabled.
  schemas:
    Error:
      type: object
      description: >-
        Error envelope. Branch on `error`; unknown codes are handled by HTTP
        status.
      required:
        - error
        - message
      properties:
        error:
          type: string
          examples:
            - invalid_partner_key
            - invalid_org_token
            - partner_disabled
            - organization_disabled
            - rate_limited
            - rate_limit_unavailable
            - code_not_found
            - code_expired
            - external_id_taken
            - invalid_user
            - job_not_found
            - user_not_found
            - run_not_found
            - candidate_not_in_run
            - invalid_decision
        message:
          type: string
      additionalProperties: true
  securitySchemes:
    partnerKey:
      type: apiKey
      in: header
      name: x-partner-key
      description: 'Partner API key: `vpk_live_` + 48 lowercase hex. Server-side only.'
    orgToken:
      type: apiKey
      in: header
      name: x-vort-org
      description: >-
        Customer org token: `vot_` + 48 lowercase hex, from /activations/redeem.
        Server-side only.

````