Receive leads with a signed webhook
Get every new lead on your server, and verify it really came from Customer360.
3 min readFor Developers
Add an Outbound webhook integration with your HTTPS URL. Customer360 POSTs each new lead as JSON with two headers:
X-Elexy-Timestamp: Unix seconds.X-Elexy-Signature:sha256=+ HMAC-SHA256 oftimestamp + "." + raw bodyusing your signing secret.
const expected = 'sha256=' + crypto.createHmac('sha256', SECRET).update(`${ts}.${rawBody}`).digest('hex');
if (!crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signature))) reject();
if (Math.abs(Date.now() / 1000 - Number(ts)) > 300) reject(); // replay protectionGood to know: Webhook URLs must be public HTTPS addresses. Private network addresses are always blocked.