Skip to main content

Test plugin reachability with a synthetic notification payload

PUT 

/v1/plugins/test

Sends a real POST from this API to plugin.url with the same shaping as production plugin notifications (JSON array body, signed with HMAC-SHA256 using plugin.token as the secret). Outbound headers include Content-Type: application/json, X-Moveo-Request-Id, optional X-Moveo-Account-Id, X-Moveo-Account-Slug, X-Moveo-Event (first element of events), X-Moveo-Signature (hex digest of the raw JSON body), and X-Moveo-Region (the cluster id of the sending deployment, e.g. eu-central). The first notification type in events selects the synthetic sample; additional types are ignored until more samples exist. Timeout is 10s. Set verify_ssl: false only for known broken certs (matches plugin verify_ssl behavior). plugin.url is constrained the same way as creating a plugin (HTTPS URIs allowed by this API). Misuse with plugins.write can still initiate connections to attacker-chosen HTTPS targets; rely on IAM and rate limits elsewhere. Returns HTTP status observed from the endpoint (may be null on TLS/DNS/connect failures), round-trip latency, and an Axios error message if the request fails. Permissions - plugins.write. API keys - manage.

Request​

Responses​

Reachability probe result from the webhook call