Webhooks
Delivery & Rotation
Responding to an event
Answer with any 2xx status as soon as you have stored the event. Do slow work afterwards — time spent before responding counts against the timeout.
- Counted as a failure: Any non-2xx status, no response within 10 seconds, or a connection that could not be made.
- Redirects are not followed: A 3xx is a failure. Register the final URL.
Retries
A failed event is tried up to 5 times in total, with exponential backoff starting at 30 seconds — roughly 30 s, 1 min, 2 min and 4 min between attempts. Every attempt carries the same event id and a fresh signature timestamp.
Every delivery is logged on the Deliveries page of the dashboard with its attempts, last status code and duration. Workspace owners and admins can replay a delivery from there.
Rotating a secret
Rotate an endpoint's secret from the Webhooks page. The new secret is shown once, and the old one keeps signing alongside it for 24 hours, so every event carries two v1 signatures during that window.
- 1. Rotate: Copy the new secret from the dashboard.
- 2. Deploy: Put it in your environment any time within 24 hours. Your handler keeps verifying with the old secret until then, because the old signature is still present.
- 3. Done: After 24 hours only the new secret signs.

