Skip to content

Receive leads with a signed webhook

Get every new lead on your server, and verify it really came from Customer360.

3 min readFor Developers

Add an Outbound webhook integration with your HTTPS URL. Customer360 POSTs each new lead as JSON with two headers:

  • X-Elexy-Timestamp: Unix seconds.
  • X-Elexy-Signature: sha256= + HMAC-SHA256 of timestamp + "." + raw body using your signing secret.
const expected = 'sha256=' + crypto.createHmac('sha256', SECRET).update(`${ts}.${rawBody}`).digest('hex');
if (!crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signature))) reject();
if (Math.abs(Date.now() / 1000 - Number(ts)) > 300) reject(); // replay protection

Good to know: Webhook URLs must be public HTTPS addresses. Private network addresses are always blocked.