React to Reach events with signed webhooks

Connect replies, prospect changes, and import results to your own system.

Open this guide in the help center →

When to use this. A reply in Reach should notify your CRM or create the next internal follow-up task.

What you’ll need. An HTTPS receiver, webhooks.write to create subscriptions, and a secure place to keep the webhook signing secret.

  1. Subscribe to the events you need

    Create a subscription in API Access or POST /api/v1/reach/webhooks. Use the intended URL and events such as prospect.created, email.replied, or import.completed. Save the signing secret shown at creation.

  2. Verify the raw request

    Read x-formbot-timestamp and x-formbot-signature. Calculate HMAC-SHA256 over timestamp + "." + the unchanged raw request body. Compare the received v1 signature with the expected value using a constant-time comparison after checking lengths.

  3. Test before processing live events

    POST /api/v1/reach/webhooks/:id/test, then inspect delivery records at /api/v1/reach/webhooks/:id/deliveries. Verify the receiver rejects a modified body or invalid signature.

  4. Handle operations carefully

    Inspect the actual event payload before mapping fields. Add duplicate handling and an appropriate timestamp/replay policy to your receiver; these are integration safeguards, not claims about an undocumented Reach retry policy.

How to know it worked

A test event reaches the receiver, passes signature verification, and produces one expected result.

Features covered

Continue learning