> ## Documentation Index
> Fetch the complete documentation index at: https://docs.collabos.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Webhooks

> Receive CollabOS events at your HTTPS endpoint.

Webhooks let your server react to CollabOS activity without repeatedly polling the API.

## Basic flow

<Steps>
  <Step title="Create an endpoint">
    Add an HTTPS webhook URL and choose at least one supported event type.
  </Step>

  <Step title="Store the signing secret">
    Keep the endpoint secret securely on your server. You need it to verify every delivery.
  </Step>

  <Step title="Verify requests before processing">
    Verify `X-Collabos-Signature` using the exact raw request body and timestamp. See [Signature verification](/webhooks/signatures).
  </Step>

  <Step title="Return a success response promptly">
    Verify the request, enqueue heavier work if needed, and respond quickly. Deliveries time out after 10 seconds.
  </Step>
</Steps>

## Personal vs workspace webhooks

Personal and workspace webhook subscriptions support different event sets. See [Webhook events](/webhooks/events).

Webhook management uses `/api/developer/...` routes authenticated with a CollabOS dashboard/session JWT. Webhook deliveries themselves are authenticated by the endpoint's signing secret.

<CardGroup cols={2}>
  <Card title="Webhook events" icon="list" href="/webhooks/events">
    See the event types available to personal and workspace endpoints.
  </Card>

  <Card title="Verify signatures" icon="shield" href="/webhooks/signatures">
    Validate the timestamp, raw request body, and HMAC-SHA256 signature.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.