Authentication
How requests between WRMS Pro and your systems are authenticated in the current release.
Audience:Developer
Webhooks: WRMS Pro → your system
Webhook requests are authenticated with a signing secret, not an API key.
- Each webhook has its own secret, beginning
whsec_. - It is shown once, when the webhook is created or the secret is rotated. It cannot be viewed again; if it is lost, rotate it.
- Every request carries an
X-WRMS-Signatureheader you verify with the secret. See Verifying signatures. - Keep the secret out of source control. Store it in your platform's secret or environment settings.
- Rotate it (Rotate signing secret) if it may have been exposed. The old secret stops working immediately.
Your system → WRMS Pro
Verification status: Not available yetThere is no public API to call in the current release, so there are no API keys, tokens or OAuth applications to set up. Do not try to automate the WRMS Pro web screens with a staff login; it is not supported, and staff accounts may use two-factor authentication.
This page will describe API authentication when a public API is released.
Still need help?
Email support@wrmspro.com or use the contact form. Signed-in users can also send a request from Settings → Support.