Skip to main content
Webhook sends the data of the event to a URL as an HTTP POST with a JSON body. It connects your workflow to anything else: an ERP, CRM, WMS, billing system, dashboard or chat channel. Webhook is available for every event, and it’s the only automation type for On Start Trip, On Finish Trip, On Geofence Entry, On Geofence Leave, On Routing Finished and On Routing Dispatched.
Required permission:
  • View automation
  • Create automation

Automation detail

Webhook detail
  1. URL: required. Where the request is sent, for example https://erp.example.com/hooks/delivery. It must be reachable from the internet and accept POST requests. Use HTTPS.
  2. Add header: add a header to the request. Without headers, the text “No header. The request is sent as-is.” is shown.
  3. Header name, for example Authorization.
  4. Header value, for example Bearer your-api-token. The trash icon removes the header.
  5. Custom JSON body: tick to replace the default body with your own JSON. See Custom JSON body.
The request is always a POST; there is no method to choose. Common headers:

Default body

Without a custom body, the request body is the record that started the automation. Task events (On Task Created, On Task Assigned, On Task Finished): the task with all its fields.
On Data Source Created: the record with all its fields.
Routing events (On Routing Finished, On Routing Dispatched): the routing result.
Trip and geofence events: see On Start Trip, On Finish Trip and On Geofence Entry.

Custom JSON body

Tick Custom JSON body to send your own JSON instead, with values from the event filled in.
Custom JSON body
  1. Insert variable: pick a field of the trigger’s task type to insert its placeholder at the cursor.
  2. Beautify: format the JSON. If the text isn’t valid JSON yet, “Cannot format — not valid JSON” is shown.
  3. Custom JSON body: the body to send. Write a value as {{key}} to have it replaced with the event’s value when the automation runs, for example "customer": "{{customerName}}".
  4. Sample payload: paste an example of the default body, for example copied from the log. It’s only used to help you write the body and is not saved.
  5. Available keys: the keys found in the sample payload. Click one to insert it at the cursor. Nested keys are written with dots, for example hub.name.
  6. Preview: the body as it would be sent for the sample payload. Keys that the sample doesn’t contain are listed as undefined: ....
Example: Untick Custom JSON body to go back to the default body.

How it works

  1. The event happens and the rules, if any, are checked.
  2. The body is prepared: the default record, or your custom body with its placeholders filled in.
  3. Your headers are added.
  4. The POST request is sent to the URL.
  5. The request, your endpoint’s status code and its response are recorded in the log, where failed requests can be retried.

Examples

Security

  • Always use HTTPS so the data is encrypted in transit.
  • Protect your endpoint with an Authorization header or an API key, and check it on every request.
  • Validate the body’s structure on your side.
  • Rotate keys regularly and keep them out of shared documents.
  • If your firewall allows it, accept requests only from known addresses.

Good practice

  • Test your endpoint before switching the automation on.
  • Answer quickly with a 2xx status and do heavy work in the background.
  • Make your endpoint idempotent, using the record’s _id, so a retried or repeated request does no harm.
  • Use rules to send only what your system needs.
  • One automation sends to one URL. To send to several, create one automation per URL.

Troubleshooting

Nothing is sent.
  • Check that the automation is Active, its event and task type match, and the rules don’t exclude the record.
  • Check that the URL is valid and reachable from the internet.
Your endpoint returns an error. Open the run in the log to see the request and the response; check the authentication header and the body your endpoint expects. The request times out. Your endpoint takes too long. Answer with 200 at once and process the data afterwards; check that the endpoint is up. You receive duplicates. Look for several automations on the same event, speed up your endpoint so it isn’t retried, and use the _id to ignore repeats.

Questions

Which HTTP method is used? Always POST, with a JSON body. Are failed webhooks retried? Failed runs stay in the log, where you can retry one or repush several at once. Delivery is not guaranteed while your endpoint is down. Can I use HTTP instead of HTTPS? It works, but it’s strongly discouraged.