Docs · Webhooks
Webhooks: every lead and sale, fanned out
Two events, any HTTPS endpoint, signed deliveries. Step-by-step automation walkthrough: Zapier integration.
How delivery works
- Events: exactly two — lead.created (Pro+) and sale.created (Growth for revenue fields). Select per endpoint in Settings → Integrations → Webhooks.
- Fan-out: every active endpoint subscribed to the event receives it — attach Zapier, Make, and Segment at once.
- Envelope (JSON): { event, workspaceId, createdAt, data } where data carries leadEventId, linkId, slug, domain, url, clickId, eventName, customerExternalId, customerEmail, customerName, saleAmount, saleCurrency.
- Signing: endpoints with a secret get slugy-timestamp + slugy-signature headers, where signature = v1=HMAC_SHA256(secret, timestamp.body). Endpoints without a secret receive unsigned POSTs (fine for Zapier/Make catch hooks).
- Retries: background delivery retries up to 8 times; each attempt is recorded in the per-endpoint delivery log with pending/success/failed status. Old deliveries are purged automatically by a scheduled job.
- Test safely: use the Send test button on the webhook card, then pause the endpoint toggle while debugging — no need to delete anything.
Verify signatures (Node)
import { createHmac, timingSafeEqual } from "crypto";
function verify(req) {
const ts = req.headers["slugy-timestamp"];
const sig = req.headers["slugy-signature"]; // v1=<hex>
const expected =
"v1=" + createHmac("sha256", SECRET).update(ts + "." + req.rawBody).digest("hex");
if (Math.abs(Date.now() / 1000 - Number(ts)) > 300) return false;
return timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
}