Send and receive webhooks
Endpoints Polzy calls, the URLs that call Polzy, and how both are signed.
Both directions in one place
Open Settings → API → Webhooks. Endpoints Polzy calls when something happens are managed there. Below them, What calls in lists every workflow trigger URL and every connector that receives calls, each with a link to where it is managed.
Add an endpoint
- Click Add endpoint.
- Enter an HTTPS address on your own system and choose the events it should receive.
- Copy the signing secret. It is shown once; afterwards only its last four characters are.
Deliveries shows every attempt to an endpoint, its result and when the next retry is. A failed delivery is retried six times over about half an hour.
Signing
Every call either way carries X-Polzy-Timestamp, X-Polzy-Signature — the HMAC-SHA256 of the timestamp and the body, made with the secret — and X-Polzy-Event-Id. A call more than five minutes old, or sent twice, is refused. The API reference shows how to check and make a signature.
Rotate a secret if it may have leaked. The old one stops working at once, so update the other side straight away.
Calls without a timestamp
A system that signs calls without X-Polzy-Timestamp still works for now, and its connector shows the date from which those calls will be refused. Admins are reminded once a week until it is fixed.
Signed-in members can ask Polzy or message the team from Support. How fast we reply depends on your plan.