Docs · Webhooks

Webhooks: every lead and sale, fanned out

Two events, any HTTPS endpoint, signed deliveries. Step-by-step automation walkthrough: Zapier integration.

How delivery works

  • Events: exactly two — lead.created (Pro+) and sale.created (Growth for revenue fields). Select per endpoint in Settings → Integrations → Webhooks.
  • Fan-out: every active endpoint subscribed to the event receives it — attach Zapier, Make, and Segment at once.
  • Envelope (JSON): { event, workspaceId, createdAt, data } where data carries leadEventId, linkId, slug, domain, url, clickId, eventName, customerExternalId, customerEmail, customerName, saleAmount, saleCurrency.
  • Signing: endpoints with a secret get slugy-timestamp + slugy-signature headers, where signature = v1=HMAC_SHA256(secret, timestamp.body). Endpoints without a secret receive unsigned POSTs (fine for Zapier/Make catch hooks).
  • Retries: background delivery retries up to 8 times; each attempt is recorded in the per-endpoint delivery log with pending/success/failed status. Old deliveries are purged automatically by a scheduled job.
  • Test safely: use the Send test button on the webhook card, then pause the endpoint toggle while debugging — no need to delete anything.

Verify signatures (Node)

import { createHmac, timingSafeEqual } from "crypto";

function verify(req) {
  const ts = req.headers["slugy-timestamp"];
  const sig = req.headers["slugy-signature"]; // v1=<hex>
  const expected =
    "v1=" + createHmac("sha256", SECRET).update(ts + "." + req.rawBody).digest("hex");
  if (Math.abs(Date.now() / 1000 - Number(ts)) > 300) return false;
  return timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
}