Available events
Use these exact event names. Names such as
message.received, connection.sent, and lead.status.changed are not the current subscription event names.
Payload
data varies by event. Deduplicate handling using eventId; do not assume deliveries arrive exactly once or in timestamp order.
Verify before processing
Workspace deliveries use Svix/Standard Webhooks signatures. Verify the unaltered raw request body and the delivery ID, timestamp, and signature headers using the official Svix library and your endpoint signing secret. Typical header names aresvix-id, svix-timestamp, and svix-signature. The library also accepts their Standard Webhooks aliases webhook-id, webhook-timestamp, and webhook-signature. This is not the older custom v1,t=...,s=... format; do not implement that parser.
See the receiver example and Svix verification documentation.
Delivery and recovery
Respond with a 2xx status after accepting the event into a durable, idempotent processing path. Keep the receiver fast. Svix controls retry timing; use the endpoint’s delivery logs for the actual attempts and redelivery controls rather than hardcoding a SendPilot five-attempt schedule. Sourcing requests can also accept a per-jobwebhook_url. Do not assume a per-job callback uses your workspace subscription’s signing secret or delivery configuration. The authenticated job-status/result endpoints remain the source for checking a sourcing outcome.
Webhook subscription management uses the signed-in dashboard and its workspace permissions. It is not an MCP tool or a public API-key /v1 route.