Skip to content

Webhook integration

The Webhook integration gives you a URL that any tool can post to: a form builder, a booking system, Zapier, Make or your own code. It’s included in every plan.

  1. Go to Settings → Integrations, choose Add integration and pick Webhook.
  2. Open it to copy its Webhook URL, which looks like https://renotify.app/webhook/integration/…, and its Signing Secret.
  3. Under Field mapping, tell Renotify where the contact’s name, phone and email are in your payload, if they aren’t in the standard places.

Include an event name, the contact, and the details your messages need under data:

Terminal window
curl https://renotify.app/webhook/integration/YOUR_TOKEN \
-H "Content-Type: application/json" \
-H "Idempotency-Key: booking-8812" \
-d '{
"event": "appointment.booked",
"contact": { "name": "Maria Chen", "phone": "+15551234567" },
"data": { "when": "Tue 14 Oct, 10:30", "location": "Harbour Street Clinic" }
}'

Renotify answers 202 with the event and contact IDs. Every automation listening for appointment.booked starts for Maria.

Without an event, the payload just adds or updates the contact.

Renotify looks for the contact’s details in these places, unless your field mapping says otherwise:

Read from
Name name, contact.name, or first_name and last_name
Phone phone or contact.phone
Email email or contact.email
Your ID external_id, id or contact.id
Marketing consent marketing_consent or opt_in

A payload needs at least a phone, an email or an ID.

Send an Idempotency-Key header, or an id in the payload, and a retried request is recorded once.

Every request needs an X-Webhook-Signature header: the HMAC-SHA256 of the raw request body with your secret, hex encoded, optionally prefixed with sha256=. Requests without a valid signature get 401.

import crypto from 'node:crypto';
const signature = crypto.createHmac('sha256', process.env.RENOTIFY_WEBHOOK_SECRET).update(rawBody).digest('hex');
// X-Webhook-Signature: sha256=<signature>

The webhook integration is for tools that can only post a payload. If you’re writing code, the events API does the same with an API key, and validates each field.