Send ticket events with webhooks
Connect the Webhooks app to post a signed JSON event to your HTTPS endpoint when a ticket is created, a customer replies or a ticket is closed.
Last updated 2 min read
The Webhooks app sends ticket events to any URL you choose. Use it to connect your own systems, or tools that are not in the app directory yet, through Zapier, Make or n8n.
Before you start
- Who can do this: owners and admins.
- Plan: all plans.
- What you need: a public HTTPS endpoint that accepts
POSTrequests with JSON, and a signing secret of at least 16 characters. - Time: about five minutes, plus building your endpoint.
Step by step
- Open Settings > Apps and choose Webhooks (under Developer).
- Type your Endpoint URL, for example
https://example.com/helpdesk-events. It must behttps. - Type a Signing secret: any long random string, at least 16 characters. Keep a copy; you need it to check signatures.
- Press Connect and test. Hushdesk sends a
pingevent, signed with your secret. - If your endpoint answers with a
2xxstatus, the card shows Connected.
What happens next
From now on, Hushdesk posts to your URL when:
- a new ticket is created (
ticket.created); - a customer replies on a ticket (
customer.replied); - a ticket is closed (
ticket.closed).
Each request carries the headers X-Hushdesk-Event, X-Hushdesk-Signature (sha256= plus a hex HMAC of the body) and User-Agent: Hushdesk-Webhooks/1. The card shows Last delivery with the event and whether it was delivered or failed, with the status code.
See Webhook events and payload for the JSON, and Verify webhook signatures for code.
Tips
- Answer with
200straight away and process the event in the background. Deliveries time out after five seconds and are not retried. - Use the ticket
idto avoid processing the same event twice in your own system. - To change the URL or secret, open the sheet, enter the new values and press Update and test.
ticket.createdandcustomer.repliedare sent after your rules have run, so tags and priority set by rules are already in the event.ticket.closedis sent when a person closes one ticket; closes made by rules or by bulk actions on several tickets do not send it.
Troubleshooting
"Your endpoint did not answer the test event with a 2xx"
Your endpoint returned an error, redirected, took longer than six seconds or could not be reached. Check it accepts POST with JSON and returns 200.
"That endpoint url does not look right"
The URL must start with https://.
"Use a signing secret of at least 16 characters"
Make the secret longer.
"Add the endpoint url"
A field is empty.
"Add the signing secret"
A field is empty.
"Endpoint URL is too long"
Keep the URL under 500 characters.
Frequently asked questions
Which events can Hushdesk send by webhook?
Three. ticket.created when a new ticket arrives, customer.replied when a customer writes again on a ticket, and ticket.closed when a ticket is closed. A ping event is also sent once, when you connect, to test your endpoint. Each event is a signed JSON POST to your URL.
Does my webhook endpoint have to use HTTPS?
Yes. The endpoint must start with https:// and point to a public internet address. Hushdesk refuses addresses inside private networks, and checks again on every delivery in case the address changes later. This protects you and other customers from requests being redirected somewhere unsafe.
Does Hushdesk retry a webhook that fails?
No. Each event is sent once, with a five-second time limit, and Hushdesk does not follow redirects. The result of the latest delivery is shown on the Webhooks card. Make your endpoint answer quickly with a 2xx code and do slow work afterwards, so no events are lost.
What is the signing secret for?
It lets your endpoint check that an event really came from Hushdesk. Hushdesk signs every body with your secret using HMAC-SHA256 and sends the result in the X-Hushdesk-Signature header. Your code computes the same signature and rejects any request where the two do not match.
Can I send webhooks to more than one URL?
One endpoint is connected per workspace. To reach several tools, point the webhook at an automation tool such as Zapier, Make or n8n and fan out from there, or at your own small service that forwards events to each place you need.
Was this helpful?
Related articles
- Webhook events and payload referenceThe exact JSON Hushdesk posts for ticket.created, customer.replied, ticket.closed and the test ping, with every field and header explained.
- Verify webhook signatures in Node, Python or PHPCheck the X-Hushdesk-Signature header so your endpoint only trusts events Hushdesk sent. Ready-to-copy code for Node.js, Python and PHP.
- Connect Zapier to HushdeskStart a Zap whenever a ticket is created, a customer replies or a ticket closes, using a Webhooks by Zapier trigger and the Hushdesk Webhooks app.
- Connect Make to HushdeskRun a Make scenario when a ticket is created, a customer replies or a ticket closes, using a Make custom webhook and the Hushdesk Webhooks app.
- Connect n8n to HushdeskTrigger an n8n workflow from Hushdesk ticket events with the n8n Webhook node, and verify the signature in a Code node on your own n8n instance.
Still stuck?
Chat with the Hushdesk team. A person answers on every plan.