Skip to main content
Workspace webhooks send signed event notifications to a server you control. Use the dashboard to manage receiver URLs, subscribed events, delivery health, and attempt history.

Create an endpoint

  1. Open Workspace settings → Webhooks.
  2. Select Create webhook.
  3. Enter a recognizable name and the complete public receiver URL.
  4. Select at least one event.
  5. Create the endpoint and copy its signing secret into your server’s secret manager.
The receiver must use HTTP or HTTPS and resolve to a public address. Biqli rejects embedded credentials, loopback, private, link-local, reserved, and unresolvable destinations. Redirect responses are not followed.

Send a test delivery

Open the webhook and select Send test event. Biqli creates a realistic event for one subscribed type and records it as a test delivery. Confirm all of the following:
  • the receiver returns HTTP 2xx;
  • the displayed attempt succeeds;
  • your server verifies Biqli-Signature against the exact raw request body;
  • the event ID is stored for deduplication; and
  • test data is not treated as a real business event.

Inspect delivery history

The webhook detail page shows delivery status, attempts, request headers and payload, response status, response headers, response body, duration, and retry timing. Use the event ID and UTC timestamps when correlating a failure with server logs. Never send a signing secret, access token, or full private receiver URL to support.

Edit or disable an endpoint

Update the name, receiver URL, or subscribed events from the configuration page. Disable an endpoint when you need to stop new production deliveries without deleting its history. Pending or retrying production deliveries are cancelled when their jobs next run after the endpoint is disabled. Test deliveries remain available for diagnosis.

Delete an endpoint

Delete an endpoint when the receiver is permanently retired or its signing secret may be exposed. Deletion removes its delivery records. Create a new endpoint to receive a new signing secret. Webhook endpoints created by an OAuth connection are also removed when that connection or its parent OAuth application is revoked. For receiver implementation, signature verification, retries, and payload contracts, continue with the Webhook introduction.