Skip to content

Create a Webhook

Register a webhook endpoint in LeadPattern, choose the events it receives, sign deliveries with a secret, and send a test before saving.

4 min readUpdated Oct 7, 2026

Creating a webhook takes two steps: Webhook Details (where to send events and how) and Select Triggers (which events to send). You need the Create / Update / Delete Webhooks permission.

Create the webhook

1

Open Webhooks

In the left sidebar, click Webhooks, then New Webhook.

2

Name it

Enter a Name your team will recognise, for example "CRM Sync Webhook".

3

Enter the Endpoint URL

Paste the public URL that should receive events. Use https:// wherever you can. Private and internal addresses (such as localhost or 10.x.x.x) are rejected.

4

Decide on signing

Sign deliveries is on by default. Keep it on and choose Generate a secret for me or Use my own secret (see below).

5

Add headers or authorization (optional)

Expand Custom headers & authorization if your endpoint needs them.

6

Send a test

Click Send test to send one test event to the URL with the current form values. The result appears right in the form, for example "Delivered — HTTP 200 in 84 ms". Nothing is saved.

7

Pick the events

Click Next Step, then tick the events this webhook should receive. Use Select all or Clear to speed things up. Select at least one event.

8

Create it

Click Create Webhook. LeadPattern sends a test event to your URL first, and the webhook is saved only if your endpoint answers with a 2xx status. If LeadPattern generated a secret, it's shown now (see below).

Signing secrets

A signing secret lets your server confirm that each delivery came from LeadPattern and wasn't changed on the way. With Sign deliveries on, every request carries the X-Webhook-Signature and X-Webhook-Signature-V2 headers.

LeadPattern creates a random secret (it starts with whsec_) when you save the webhook. It's shown once, on the Webhook created — save your signing secret screen. Click Copy, store it somewhere safe, such as your server's environment variables, then click I've stored the secret. You can't view it again later. If you lose it, rotate it.

Custom headers & authorization

Expand Custom headers & authorization to send extra information with every delivery:

  • Authorization: choose None, Bearer token (sent as Authorization: Bearer <token>) or Basic auth (username and password).
  • Custom headers: up to 20 name/value pairs, such as an API key your gateway expects. Some names are reserved and can't be used: Host, Content-Type, Content-Length, User-Agent, connection-level headers, Proxy-Authorization, and anything starting with X-Webhook-.

After you save, header values and credentials are masked. They're never shown again, and an empty field keeps the stored value when you edit.

What's next

Was this article helpful?

Your feedback helps us continuously improve our documentation.

Need more help with this topic?Ask LeadPattern Support

Related Articles