Skip to main content
Webhooks send events, such as incoming messages, to your HTTPS endpoint. Manage endpoints with webhooks on a team or project client, and check each request with the webhooks utilities. Project endpoints receive the project’s Number events, such as messages and calls. Team endpoints receive team events, such as customer and campaign lifecycle events. See Webhooks for every event type.

Create an endpoint

Store the signing secret in your secret manager. The API returns it only in this response. secretAvailable is false when the response cannot include it. Change an endpoint with update(webhookId, { ... }). Set enabled: false to pause deliveries, and call delete(webhookId) to remove it.

Verify a webhook

Every delivery carries an x-webhook-signature header. Verify it against the exact request bytes before you read the event:
This handler runs as a Cloudflare Worker. The same webhooks.verify call works in any handler that can read the raw body, including Node.js, Deno, and Bun. Read the body as bytes. Parsing the JSON and serializing it again changes the bytes and breaks the signature. webhooks.verify rejects a bad signature before it parses the body. Use webhooks.verifySignature to get a true or false result without parsing. Delivery retries reuse the event id. Store processed IDs and skip repeats.

Handle each event type

isEvent narrows an event to its payload type:
Event types the installed SDK does not know still verify. Their payload is not typed.

Send a test delivery

On a team client, test accepts only eventType. On a project client, it also accepts a base64-encoded native event body together with the sessionId of a Number in that project. See Send a test delivery.

Test your receiver without the API

webhooks.createFixture signs an event body locally, with no API call. Use it in unit tests:
Pass fixture.body to your handler as is. Use a test secret, never a production one. Fixtures cover the native format only. Endpoints that use the Meta format are signed with the X-Hub-Signature-256 header. See Delivery formats.

Rotate a signing secret

The response returns the new secret once. The previous secret stays valid until previousValidUntil. Deploy the new secret to your receiver before then.

Inspect and retry deliveries

listAttempts(deliveryId) and retrieveAttempt(deliveryId, attemptId) show each attempt. A failed attempt includes a redacted excerpt of your endpoint’s response. To send an older event again, see Replay an event.