Webhook events and payload reference
The exact JSON Hushdesk posts for ticket.created, customer.replied, ticket.closed and the test ping, with every field and header explained.
Last updated 2 min read
This is the reference for the JSON that the Webhooks app sends. Every event is a POST with Content-Type: application/json.
Before you start
- Who this is for: developers building an endpoint, or anyone mapping fields in Zapier, Make or n8n.
- Plan: all plans.
- What you need: the Webhooks app connected. See Send ticket events with webhooks.
Step by step
- Connect the Webhooks app. The first request your endpoint receives is a
ping. - Create a test ticket, for example by emailing your support address, to receive
ticket.created. - Reply as the customer to receive
customer.replied. - Close the ticket in the inbox to receive
ticket.closed. - Map the fields you need in your tool or code.
What happens next
Headers
| Header | Value |
|---|---|
Content-Type |
application/json |
User-Agent |
Hushdesk-Webhooks/1 |
X-Hushdesk-Event |
The event name |
X-Hushdesk-Signature |
sha256= followed by the hex HMAC-SHA256 of the raw body, keyed with your signing secret |
Ticket event body
{
"event": "ticket.created",
"at": "2026-10-08T09:15:02.481Z",
"workspace_id": "…",
"ticket": {
"id": "…",
"subject": "Where is my order #1042?",
"status": "open",
"channel": "email",
"priority": 0,
"tags": ["wismo"],
"url": "https://your-hushdesk-address/app/inbox?c=…",
"customer": { "email": "sam@example.com", "name": "Sam Lee" },
"last_message": "Hi, my parcel has not arrived yet…"
}
}
Test ping body
{ "event": "ping", "at": "2026-10-08T09:10:00.000Z" }
Fields
| Field | Meaning |
|---|---|
event |
ticket.created, customer.replied, ticket.closed or ping |
at |
When the event was sent (ISO 8601, UTC) |
ticket.status |
open, pending (waiting on the customer), snoozed, closed or spam |
ticket.channel |
email or chat |
ticket.priority |
-1 Low, 0 Normal, 1 High, 2 Critical |
ticket.tags |
Tag names on the ticket |
ticket.url |
Opens the ticket in Hushdesk |
ticket.customer |
email and name, either may be null |
ticket.last_message |
The customer's latest message, up to 2,000 characters |
Tips
- Read the event name from
X-Hushdesk-Eventor theeventfield; they always match. - Verify the signature over the raw body before parsing it. See Verify webhook signatures.
- Treat unknown fields as optional. New fields may be added later; existing ones keep their meaning.
Troubleshooting
My endpoint gets the ping but no ticket events
Ticket events start with the next new ticket, customer reply or close. Create a test ticket to check.
"Your endpoint did not answer the test event with a 2xx"
The ping failed. Return 200 for ping events as well.
Frequently asked questions
What fields are in a Hushdesk webhook?
Every event has event, at, workspace_id and a ticket object. The ticket has id, subject, status, channel, priority, tags, url, the customer's email and name, and last_message with up to 2,000 characters of the customer's latest message. The test ping has only event and at.
Does the webhook include the full conversation?
No. To keep events small and safe, only the customer's latest message is included, cut to 2,000 characters. Use the url field to open the full ticket in Hushdesk. Internal notes and agent replies are never sent in webhook events.
What do the priority numbers in a webhook mean?
Priority is a number. -1 means Low, 0 Normal, 1 High and 2 Critical, the same four levels you pick in the ticket header. Rules can set priority too, so a rule that marks urgent words as Critical changes the value later events carry.
When is customer.replied sent?
Each time a customer writes again on an existing ticket, by email or in chat, after your rules for customer replies have run. A reply that reopens a closed ticket also sends customer.replied. A brand-new email or chat that starts a ticket sends ticket.created instead.
Does closing a ticket with a rule send ticket.closed?
No. ticket.closed is sent when a person closes a ticket, from the ticket header, with Send and close or from the ticket's status. Tickets closed by a rule, including time-based rules that close after no reply, are recorded in the ticket's activity log but do not send a webhook.
Was this helpful?
Related articles
- Send ticket events with webhooksConnect the Webhooks app to post a signed JSON event to your HTTPS endpoint when a ticket is created, a customer replies or a ticket is closed.
- Verify webhook signatures in Node, Python or PHPCheck the X-Hushdesk-Signature header so your endpoint only trusts events Hushdesk sent. Ready-to-copy code for Node.js, Python and PHP.
- Connect Zapier to HushdeskStart a Zap whenever a ticket is created, a customer replies or a ticket closes, using a Webhooks by Zapier trigger and the Hushdesk Webhooks app.
Still stuck?
Chat with the Hushdesk team. A person answers on every plan.