Verify and reconcile Ideogram async webhooks with Ed25519 signatures, replay controls, deduplication, and polling fallback. Use when implementing or auditing an event receiver. Trigger with "verify an Ideogram webhook", "build Ideogram async callbacks", or "debug duplicate Ideogram events".
Accept Ideogram asynchronous completion only after cryptographic verification and idempotent reconciliation. Use the raw request body, bind all signed headers, acknowledge quickly, and retain polling as a recovery path because delivery is not guaranteed.
generation_id, destination object policy, and polling reconciler.Async requests can include a webhook URL and return generation_id. Ideogram signs callbacks with Ed25519 and publishes keys at https://api.ideogram.ai/v1/.well-known/jwks.json. Signed headers identify generation, user, timestamp, key, and signature. Deliveries may duplicate, retries are limited, and polling remains necessary.
Webhook trust comes from signature verification, not a shared API key in the callback. Normal polling uses server-side IDEOGRAM_API_KEY in the Api-Key header; never expose it to the receiver request.
2xx quickly, and enqueue processing.GET /v1/generations/ and poll that resource.Use Read, Glob, and Grep for receiver, queue, state, and fixtures. Use Write and Edit for approved implementation and tests. Do not expose a receiver, submit paid async work, or replay production events by invocation alone.
Require approval for public routing, production keys, live submissions, replay-window changes, retained identifiers, and storage or publishing. Reject callbacks that cannot be tied to an authorized application operation.
Return receiver route class, signature and replay result, opaque generation ID, duplicate state, acknowledgment latency, downstream terminal and storage state, polling fallback, and cleanup. Exclude headers, bodies, URLs, prompts, and images.
signature=pass; replay=fresh; duplicate=yes; transitions=1; poll_fallback=not-needed.Test byte mutation, header mutation, stale timestamps, unknown and rotated keys, duplicates, out-of-order state, unsafe output, polling fallback, and object deletion. Confirm receiver logs contain no signed body or content.
88dcf65
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.