SIG9
GLOSSARY · MAINTAIN

Webhook

A webhook is an automatic message one app sends to another the moment something happens in it, like a form submitted or an invoice paid. The other app doesn't have to keep checking for news. In plain English, it's a doorbell: you hear when someone arrives, instead of checking the window every few minutes.

Why it matters

Most of the tools a service business runs, like forms, scheduling, payments and the CRM, can send webhooks. They're how one event starts a chain of work without anyone copying data across. They also fail in ways an owner rarely sees. If the receiving end is down when the message arrives, some tools try again a few times and give up, others never retry, and the lead or the order never shows up where it should.

An example

Say an agency's website form sends a webhook each time someone fills it in. The receiving workflow adds the lead to the CRM, tells the right person in chat and sends a confirmation. One evening the workflow is paused for an edit, and a few leads come in while it's off. If nothing kept those messages, those leads exist only in the form tool's history, and nobody is going to look there.

How a system handles it

A system keeps every incoming webhook before it acts on it. It stores the message, answers the sender right away and then does the work, so a slow step never makes the sender give up. Each message carries a unique key that's checked on arrival, so a retry from the sender doesn't create the same lead twice. If a step fails, the message stays stored and whoever owns the system gets an alert, so it can run again once the fault is fixed.

Questions

What's the difference between a webhook and an API?

An API is how one app asks another for something, whenever it wants. A webhook is the other app telling it, as soon as something happens. Most integrations use both: a webhook says a new lead arrived, and an API call fetches or updates the details.

Are webhooks secure?

They can be. A webhook arrives at a web address anyone could post to, so the receiving side should check a shared secret or signature on every message and reject anything without it. That's a setup step, so ask whoever builds your automations whether it was done.

Mashrur Rahman · Founder, SignalNinePUBLISHED · UPDATED