Send and receive webhooks

Endpoints Polzy calls, the URLs that call Polzy, and how both are signed.

Polzy team3 min readUpdated 3 Oct 2026Team and up
On this page
  1. 1Both directions in one place
  2. 2Add an endpoint
  3. 3Signing
  4. 4Calls without a timestamp

Both directions in one place

Open Settings → API → Webhooks. Endpoints Polzy calls when something happens are managed there. Below them, What calls in lists every workflow trigger URL and every connector that receives calls, each with a link to where it is managed.

Add an endpoint

  1. Click Add endpoint.
  2. Enter an HTTPS address on your own system and choose the events it should receive.
  3. Copy the signing secret. It is shown once; afterwards only its last four characters are.

Deliveries shows every attempt to an endpoint, its result and when the next retry is. A failed delivery is retried six times over about half an hour.

Signing

Every call either way carries X-Polzy-Timestamp, X-Polzy-Signature — the HMAC-SHA256 of the timestamp and the body, made with the secret — and X-Polzy-Event-Id. A call more than five minutes old, or sent twice, is refused. The API reference shows how to check and make a signature.

Rotate a secret if it may have leaked. The old one stops working at once, so update the other side straight away.

Calls without a timestamp

A system that signs calls without X-Polzy-Timestamp still works for now, and its connector shows the date from which those calls will be refused. Admins are reminded once a week until it is fixed.

Was this helpful?
Still stuck?

Signed-in members can ask Polzy or message the team from Support. How fast we reply depends on your plan.