Webhook

A webhook is an HTTP request that one system sends automatically to a URL provided by another system when a specific event happens, such as a new reply or a status change, so the receiver learns about it without polling.

AI & Sales AutomationUpdated September 30, 2026

In short

A webhook is an automatic HTTP callback that pushes an event to your system the moment it happens.

Key points

  1. Webhooks push events to a receiver; polling a REST API pulls them, usually with more delay and more requests [1][2].
  2. Most webhooks are POST requests with a JSON body describing the event [2].
  3. Receivers should verify a signature, often an HMAC of the payload with a shared secret, before trusting the data [3][4].
  4. Senders retry on failure, so receivers should respond quickly and handle duplicate deliveries safely [3].
  5. Webhooks are a common trigger for Workflow Automation, such as updating a CRM (Customer Relationship Management) when a reply arrives.

How webhooks work

A webhook reverses the usual direction of an API call. Instead of your system asking another service whether anything changed, the service calls you. You register a URL and choose which events you care about; when one happens, the service sends an HTTP POST to that URL with a payload describing the event [1]. GitHub's documentation explains the trade-off clearly: webhooks deliver data as events happen and use fewer resources than repeatedly polling an API [2]. Typical events in sales tools include a new reply, a bounce, an unsubscribe, a deal changing stage or a new record being created. The receiving endpoint processes the payload and returns a success status code, usually 2xx, to confirm receipt.

Security and reliability

Because a webhook URL is reachable from the internet, the receiver must check that each request is genuine. The common method is a signature: the sender computes an HMAC of the payload with a shared secret and puts it in a header, and the receiver recomputes and compares it. Stripe also includes a timestamp in the signed data to block replay attacks [3]. The Standard Webhooks specification describes this pattern as a shared convention across providers [4]. Reliability needs care too. Senders retry failed deliveries, so the same event can arrive twice; receivers should store an event ID and ignore duplicates. Endpoints should acknowledge quickly and do slow work in the background, because long processing can trigger timeouts and more retries.

Webhooks in sales automation

Webhooks are the glue between tools in a sales stack. When Reply Detection in an outreach tool sees an answer, a webhook can tell the CRM (Customer Relationship Management) to log it and alert the rep, which shortens Speed to Lead. When a prospect unsubscribes, a webhook can add them to a shared Suppression List so no other tool emails them. When a deal closes, a webhook can start onboarding. These events drive Workflow Automation without anyone copying data by hand. Treat webhook data as input from outside your system: validate it, keep the secret out of code by storing it the way you would an API Key, and monitor for failed deliveries so a silent break does not leave replies unanswered. If a third-party service receives contact data through webhooks, it is processing that data for you, which usually calls for a Data Processing Agreement (DPA) where the GDPR applies.

Sources
  1. Webhook — Wikipedia
  2. About webhooks — GitHub Docs
  3. Receive Stripe events in your webhook endpoint — Stripe Documentation
  4. Standard Webhooks — standardwebhooks.com
External sources open in a new tab.

Related terms

Mentioned in

Outreach without the busywork.

PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.

Start free with 100 credits →