API reference

Video rendering API

Submit JSON to Rendofy, receive a queued job acknowledgement, and collect the completed MP4 URL through your callback endpoint.

Account credentials

Your signing secret starts with whsec_ and is displayed in your sandbox key modal or returned via GET /v1/account/keys.

curl https://api.rendofy.com/v1/account/keys \
  -H "Authorization: Bearer $RENDOFY_API_KEY"

Keep both API key and webhook signing secret in server-side secret storage. The account lookup endpoint requires the API key as a Bearer token.

Submit a render

curl -X POST https://api.rendofy.com/webhook/render-intake \
  -H 'Content-Type: application/json' \
  -d "$(jq -n --arg key "$RENDOFY_API_KEY" --arg callback "$CALLBACK_URL" '{api_key:$key,callback_url:$callback,payload:{quote:"Ship it",author:"Rendofy"}}')"

Successful submissions return HTTP 202 with status queued and a job_id. Reuse the same Idempotency-Key when retrying a request to avoid creating duplicate jobs. Capacity rejection returns HTTP 429 and Retry-After: 5.

Verify callback signature

Callbacks include Rendofy-Signature in the form t=<unix-seconds>,v1=<hex-hmac>. Verify HMAC-SHA256 over the exact raw request body prefixed by the timestamp and a period.

import { createHmac, timingSafeEqual } from 'node:crypto';
const [t, v1] = req.headers['rendofy-signature'].split(',').map(part => part.split('='));
const expected = createHmac('sha256', process.env.RENDOFY_WEBHOOK_SECRET)
  .update(`${t[1]}.${rawBody}`).digest();
const supplied = Buffer.from(v1[1], 'hex');
const valid = supplied.length === expected.length && timingSafeEqual(supplied, expected);
if (!valid) throw new Error('Invalid Rendofy callback signature');
Important: verify against raw bytes before parsing JSON, then validate timestamp freshness and match job_id to your pending request.