Manage Webhooks
Edit LeadPattern webhooks, rotate or replace signing secrets with a 24-hour grace period, pause and resume deliveries, and understand each status badge.
Everything here needs the Create / Update / Delete Webhooks permission. Members with only View Webhooks & Delivery Logs can see the list and open delivery logs.
Status badges
The Status column shows the state of each webhook:
| Badge | Meaning |
|---|---|
| Active | Deliveries are being sent. |
| Paused manually | Someone paused the webhook. Resume it when you're ready. |
| Plan limit | Disabled because your plan's webhook limit was reached. Delete another webhook or upgrade your plan to re-enable it. |
| Auto-disabled after failures | Delivery failed for 50 events in a row. The row shows the number of consecutive failed deliveries and the time of the last failure. See Logs & retries. |
Next to the name you may also see:
- Signed: deliveries carry signature headers. A clock icon means a secret was recently rotated and the previous one is still accepted.
- Not secure: the endpoint uses
http://, so deliveries aren't encrypted.
Edit a webhook
Click the Edit (pencil) icon to change the name, URL, events, headers or authorization, then click Update Webhook.
Changing the URL, custom headers, authorization or secret of an active webhook sends a test event
before saving. The change is saved only if your endpoint answers with 2xx. Changing just the
name or events saves straight away.
Send test works here too. With unsaved changes, it tests the form values and shows the HTTP result immediately. With no changes, it queues a test event using the saved settings, and the result appears in the delivery logs.
Signing secret
In the edit form, the Sign deliveries section shows whether the webhook is Signed or Not signed. Changes in this section are saved immediately.
Rotate secret / Generate secret
Rotate secret creates a new secret and shows it once. Copy it. The old secret keeps
working for 24 hours. During that time each delivery carries signatures from both secrets:
X-Webhook-Signature / X-Webhook-Signature-V2 use the new secret, and
X-Webhook-Signature-Previous / X-Webhook-Signature-V2-Previous use the old one. Update
your server within that window. If the webhook isn't signed yet, the button reads Generate
secret.
Use my own secret…
Enter your own secret (16–128 characters) and click Save secret. It replaces the current secret immediately.
Remove secret
Stops signing. Deliveries no longer include the X-Webhook-Signature headers, so a server
that checks signatures will start rejecting them. Switching Sign deliveries off does the
same.
Pause, resume and delete
- Pause / Resume. Click the pause or play icon. A paused webhook shows Paused manually
and receives no events. Resuming sends a test event first, and the webhook turns back on only if
your endpoint answers with
2xx. Resuming a webhook that was Auto-disabled after failures also resets the failure count, so fix the endpoint first. - Delete. Click the trash icon and confirm. The webhook is removed permanently, and its delivery logs are deleted after 30 days.
What's next
Was this article helpful?
Your feedback helps us continuously improve our documentation.
Related Articles
Create a Webhook
Register a webhook endpoint in LeadPattern, choose the events it receives, sign deliveries with a secret, and send a test before saving.
Verify Webhook Signatures
Why you should sign LeadPattern webhook deliveries, how to turn signing on, and how to verify the HMAC-SHA256 X-Webhook-Signature headers, with Node.js and Python examples that handle secret rotation.
Webhook Logs & Retries
How LeadPattern retries failed webhook deliveries for about 24 hours, how to redeliver a failed event, when a webhook is auto-disabled, and how to read the 30-day delivery logs.
Webhook Events
The 41 LeadPattern webhook events (messages, conversations, contacts, notes, flows, calls and WooCommerce) and the envelope every delivery uses.

