Create a Webhook
Register a webhook endpoint in LeadPattern, choose the events it receives, sign deliveries with a secret, and send a test before saving.
Creating a webhook takes two steps: Webhook Details (where to send events and how) and Select Triggers (which events to send). You need the Create / Update / Delete Webhooks permission.
Create the webhook
Open Webhooks
In the left sidebar, click Webhooks, then New Webhook.
Name it
Enter a Name your team will recognise, for example "CRM Sync Webhook".
Enter the Endpoint URL
Paste the public URL that should receive events. Use https:// wherever you can. Private and
internal addresses (such as localhost or 10.x.x.x) are rejected.
Decide on signing
Sign deliveries is on by default. Keep it on and choose Generate a secret for me or Use my own secret (see below).
Add headers or authorization (optional)
Expand Custom headers & authorization if your endpoint needs them.
Send a test
Click Send test to send one test event to the URL with the current form values. The result appears right in the form, for example "Delivered — HTTP 200 in 84 ms". Nothing is saved.
Pick the events
Click Next Step, then tick the events this webhook should receive. Use Select all or Clear to speed things up. Select at least one event.
Create it
Click Create Webhook. LeadPattern sends a test event to your URL first, and the webhook is
saved only if your endpoint answers with a 2xx status. If LeadPattern generated a secret,
it's shown now (see below).
Signing secrets
A signing secret lets your server confirm that each delivery came from LeadPattern and wasn't
changed on the way. With Sign deliveries on, every request carries the X-Webhook-Signature
and X-Webhook-Signature-V2 headers.
LeadPattern creates a random secret (it starts with whsec_) when you save the webhook. It's
shown once, on the Webhook created — save your signing secret screen. Click Copy,
store it somewhere safe, such as your server's environment variables, then click I've stored
the secret. You can't view it again later. If you lose it, rotate it.
Custom headers & authorization
Expand Custom headers & authorization to send extra information with every delivery:
- Authorization: choose None, Bearer token (sent as
Authorization: Bearer <token>) or Basic auth (username and password). - Custom headers: up to 20 name/value pairs, such as an API key your gateway expects. Some
names are reserved and can't be used:
Host,Content-Type,Content-Length,User-Agent, connection-level headers,Proxy-Authorization, and anything starting withX-Webhook-.
After you save, header values and credentials are masked. They're never shown again, and an empty field keeps the stored value when you edit.
What's next
Was this article helpful?
Your feedback helps us continuously improve our documentation.
Related Articles
Webhooks Overview
LeadPattern webhooks send real-time events, such as new messages, chat assignments and calls, to your own server as signed HTTPS POST requests.
Webhook Events
The 41 LeadPattern webhook events (messages, conversations, contacts, notes, flows, calls and WooCommerce) and the envelope every delivery uses.
Verify Webhook Signatures
Why you should sign LeadPattern webhook deliveries, how to turn signing on, and how to verify the HMAC-SHA256 X-Webhook-Signature headers, with Node.js and Python examples that handle secret rotation.
Manage Webhooks
Edit LeadPattern webhooks, rotate or replace signing secrets with a 24-hour grace period, pause and resume deliveries, and understand each status badge.

