Quick tipDeveloperData HubMarketing Hub

Send a webhook from a workflow, and verify it really came from HubSpot

A workflow webhook is the simplest way to push a record to another system when something changes.

Subscription
Check your subscription for the webhook action
Permissions
Workflows access
Time
4 min · Advanced
Last verified

Short answer

Send a webhook sends record data to your URL when the workflow reaches it. With Request signature authentication, HubSpot adds X-HubSpot-Signature: a SHA-256 hash of your app secret, the HTTP method, the URI and the raw body. HubSpot's developer blog notes the signature is only sent when you add a valid app ID. Compare the hash on your server and reject mismatches.

1. Where it is

Workflow action picker Data ops group with Send a webhook highlighted
Send a webhook (1).

2. Validate on your side

expected = sha256(app_secret + method + uri + raw_body)  // hex
if (expected !== request.headers['x-hubspot-signature']) reject(400)

Workflow webhook requests use signature version 2, set in the X-HubSpot-Signature-Version header. Use the raw body exactly as received.

3. When to use something else

For many events from many records, app webhooks scale better. See webhooks. For logic inside HubSpot, see custom code actions.

Sources

New field notes by email

One email when a new article publishes.

Still stuck?

If this did not fix it, the problem is probably specific to your setup. Book a call and we will look at it together.

Book a call with Sam