Skip to navigation

Trigger from a Webhook

View as Markdown

When you want another system, such as a website form or your CRM, to start a workflow the moment something happens, you use a webhook. It gives your workflow a private URL that the other system calls, and the details it sends come into the run so later steps can use them.

Nodes involved

  • The Start node, configured as a webhook trigger.

How to build it

1

Configure the Start node as a webhook

On the Start node, set it up as a webhook trigger and define the fields you expect the caller to send. See Triggers & Webhooks for the full detail.

2

Get the URL

Publish the workflow to get its webhook URL. Only published workflows have a working URL. The URL is the credential: anyone who has it can start this one workflow, so give it only to the system that needs it and keep it out of anywhere public.

3

Require a shared secret (optional)

If you want a value you can change later without recreating the workflow, add a shared secret to the Start node’s webhook settings and have the caller send it with every request. Put it in a request header if the calling system lets you set one. Editing the secret and publishing cuts off anyone still sending the old value, on the very next request. See Triggers & Webhooks for what a shared secret does and does not protect you from.

4

Reference the incoming data downstream

The information the caller sends is available to later steps through the Start node. Point a field at an incoming value like this:

start.body.email

Use whichever field names the caller actually sends.

5

Test it

Send a sample request to the URL and watch the run in Testing & Debugging to confirm the incoming data arrived where you expect. While you are still building, you can also start runs by hand from there.

Treat the webhook URL like a password. Anyone holding it can start this workflow, and adding a shared secret does not change that, because you have to give the caller the secret too. When a caller needs to genuinely prove who it is, start the workflow the way that requires real credentials instead. See Triggers & Webhooks.