Keep every connected system current.
Send signed conversation and campaign events to the systems your business already uses.
Webhook delivery
Customer message received
Keep every action clear and accountable.
Send conversation and campaign events to the systems your business already uses. Signed webhooks let your own tools receive changes as they happen and decide what to do next.
Subscribe an endpoint to the events you care about
Every delivery signed so you can verify it came from us
Failures counted, with automatic disabling of a dead endpoint
API keys minted with scopes and revoked when needed
What keeps the work controlled
Events your systems can use
Outbound events carry the event type, time and business context your systems need to process them.
- Conversation, send, approval, contact and channel events
- Event details that match the activity history
- One business only
Signed and verifiable
Any public endpoint receives noise. A signature computed with your own secret is how your system tells a real delivery from a forged one.
- Signature computed with a per endpoint secret
- Secret shown once at creation and rotatable afterwards
- Endpoints enabled, disabled and deleted from the business
More capabilities
Register an endpoint
Add the URL that should receive events and choose which ones it subscribes to, so an endpoint only gets what it asked for.
Store the secret
A signing secret is shown once when the endpoint is created. Keep it, because it is what proves a delivery came from your business.
Verify and act
Check the signature on each delivery before you trust it, then do whatever your system needs to do with the event.
Watch the health
Failures are counted per endpoint, and an endpoint that keeps failing is disabled.
Keys with scopes
Keys are minted in the business, shown once, listed masked afterwards, and carry the scopes that decide what they can reach.
- Mint a key with the scopes it needs
- Listed masked, with when it was last used
- Revoked immediately when it should stop working
- Key creation and revocation written to the activity history
The public API, Soon
Endpoints for contacts, conversations, messages and campaigns, authenticated with your business keys and following the same permission and consent rules the interface does.
- Read and write endpoints under a versioned path
- Cursor pagination and a consistent error shape
- Duplicate requests blocked before sending
- The same consent and reply-window rules as the interface
Good to know
- Webhooks deliver events. They are not a way to send messages into Otobiz.
- There is no single export of an entire business beyond contacts.
Questions buyers ask
What events can I subscribe to?
Business events from the activity history, covering conversations, sends, approvals, contacts and channel integrations. An endpoint receives only what it subscribes to.
How do I verify a delivery?
Each delivery is signed with the secret shown when you created the endpoint. Compute the signature over the payload and compare before trusting it.
What if my endpoint goes down?
Failures are counted, and an endpoint that keeps failing is disabled. Re-enable it once your service is back.
Can I rotate the signing secret?
Yes. Rotation is supported so a leaked secret can be replaced without deleting the endpoint and its subscriptions.
More questions
- Is there a public API?, Soon
- Signed webhooks can send selected events to your systems. Public API access is a separate capability.
- Will API sends bypass consent?
- No. Anything that sends passes the same consent, suppression, conversation window and duplicate protection as a message sent from the interface.
- Are API keys scoped?
- Yes. A key carries scopes, is listed masked after creation, records when it was last used and can be revoked immediately.
- Can I export data instead?
- Contacts export to CSV from the business. For a continuous feed, webhooks are the intended path.
- Will I receive duplicate deliveries?
- Delivery is at least once, which is normal for webhooks. Treat the event identifier as the key and make your handler safe to run twice.
Bring customers back with timely follow-ups.
Ready to put this to work?
Start with one customer journey and build from there.
7-day free trial. Nothing is charged when you start. Cancel before it ends and pay nothing.