वेबहुक
BeeCastly में कुछ होने पर अपने सर्वर पर HTTPS कॉल पाएँ: नया लीड, बुकिंग, दुकान का ऑर्डर या आने वाला WhatsApp संदेश।
Setup
- Open Integrations → Webhooks & API in your dashboard and click Add webhook.
- Enter your endpoint URL. It must be
https://and resolve to a public address. - Pick the events to receive.
- Copy the signing secret (
whsec_…) from the dialog that opens. It is shown once. Lost it? Click Regenerate on the endpoint — the old secret stops working at once. - Click Test to send a
test.pingevent and confirm your receiver answers.
The number of endpoints depends on your plan (Free 2, Starter 10, Growth 30, Pro 100, Agency unlimited). Creating one past the limit returns 402 with code WEBHOOK_LIMIT.
Events
lead.createdA funnel or form captured a lead.booking.createdA booking was made.order.createdA storefront order was placed.message.receivedAn inbound message arrived in your inbox.The request
One POST per event per endpoint, JSON body of event, data and timestamp:
POST https://your-server.example/beecastly
Content-Type: application/json
User-Agent: BeeCastly-Webhooks/1.0
X-BeeCastly-Event: message.received
X-BeeCastly-Signature: sha256=5d41402abc4b2a76b9719d911017c592…
{
"event": "message.received",
"data": {
"messageId": "cmg8x2k1…",
"conversationId": "cmg8x2j9…",
"from": "12025551234",
"text": "Hello!",
"contactId": "cmg1k9…",
"contactName": "John Doe",
"contactPhone": "+12025551234",
"receivedAt": "2026-10-05T12:00:00.000Z"
},
"timestamp": "2026-10-05T12:00:00.412Z"
}Verifying the signature
X-BeeCastly-Signature is sha256= followed by the hex HMAC-SHA256 of the raw request body, keyed with your endpoint's signing secret. Compute it over the bytes you received — parsing the JSON and serialising it again can change the bytes, and the signature will not match.
// Node.js / Express
const crypto = require('crypto');
app.post('/beecastly', express.raw({ type: 'application/json' }), (req, res) => {
const expected = 'sha256=' + crypto
.createHmac('sha256', process.env.BEECASTLY_WEBHOOK_SECRET) // whsec_…
.update(req.body) // the raw Buffer
.digest('hex');
const got = req.get('X-BeeCastly-Signature') || '';
const ok = got.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(got), Buffer.from(expected));
if (!ok) return res.sendStatus(401);
const { event, data } = JSON.parse(req.body);
// …handle the event, idempotently (see Retries)
res.sendStatus(200);
});Retries
- Answer with a 2xx status within 8 seconds. Redirects are not followed.
- A failed delivery is retried, up to 5 attempts in all, with exponential backoff from 5 seconds. If one of several endpoints fails, the retry re-sends to all of them, so handle each event idempotently.
- After 5 failed deliveries in a row you are notified. The endpoint is not paused automatically — pause or delete it from the dashboard.