REST API, webhooks, tokens.
Generate a Bearer token from the customer portal and call your first endpoint.
Every outbound webhook is signed with HMAC-SHA256.