App routes
Apps can expose HTTP routes from their logic functions under/s/. The workspace is taken from the host (<your-org>.hermios.app) or from the bearer token. Routes marked as requiring auth need a token; others, such as signed webhooks, are public and must verify their own signature.
The Documenso app, for example, receives Documenso’s signing webhooks at /s/documenso/webhook.