Basic flow
1
Create an endpoint
Add an HTTPS webhook URL and choose at least one supported event type.
2
Store the signing secret
Keep the endpoint secret securely on your server. You need it to verify every delivery.
3
Verify requests before processing
Verify
X-Collabos-Signature using the exact raw request body and timestamp. See Signature verification.4
Return a success response promptly
Verify the request, enqueue heavier work if needed, and respond quickly. Deliveries time out after 10 seconds.
Personal vs workspace webhooks
Personal and workspace webhook subscriptions support different event sets. See Webhook events. Webhook management uses/api/developer/... routes authenticated with a CollabOS dashboard/session JWT. Webhook deliveries themselves are authenticated by the endpoint’s signing secret.
Webhook events
See the event types available to personal and workspace endpoints.
Verify signatures
Validate the timestamp, raw request body, and HMAC-SHA256 signature.