A webhook sends an HTTPS request from Mateflow to a URL you control whenever something happens in your community, such as a new member joining or a payment arriving. Use webhooks to keep a CRM, email tool, or your own app in sync. You set them up under Admin → Settings → Integrations → Webhooks.
Who can do this: Owners and admins. · Where: Web (admin console). · Plan: Webhooks, and how many you can create, depend on your platform plan.
Create a webhook endpoint
- Go to Admin → Settings → Integrations and open the Webhooks tab.
- Click Add Webhook.
- Enter a Name (under 100 characters) and the Endpoint URL. The URL must use HTTPS.
- Optional but recommended: under Secret (optional), click the generate button (Generate secret) and copy the secret for your server. See the signature section below.
- Under Events, tick the events to send. Tick a category name to select all of its events.
- Leave Active on so the webhook starts receiving events.
- Click Create Webhook.
If the Add Webhook button shows an upgrade prompt, your plan doesn't include webhooks or you've reached your plan's webhook limit. See Check plan usage and limits.
Webhook events you can subscribe to
| Category | Events |
|---|---|
| Members | Member Joined, Role Changed, Member Suspended (also sent for bans), Member Reinstated, Member Added to Access Group, Member Removed from Access Group |
| Content | Post Created, Comment Created, Post Deleted, Comment Deleted |
| Payments | Payment Received, Payment Failed, Subscription Created, Subscription Renewed, Subscription Canceled, Refund Issued |
Older webhooks may show events that are no longer available. You can remove them, but you can't add them again.
How access group webhook events work
Member Added to Access Group and Member Removed from Access Group (access groups were previously called member tiers) fire when a member's groups actually change. Each event covers one member and one group, and includes the member's username and email, the group's name, and what caused the change: an admin, a subscription, an invitation, the default access group, or a deleted group.
- No access group event is sent before Member Joined, so a new member's default group at sign-up isn't announced, and neither are changes while a member waits for approval.
- Deleting an access group sends one removal event per member who held it. These, and events from setting a default group, can arrive a few minutes later.
- Removing a group that a subscription grants sends a removal and then an addition, because the subscription adds it back right away. See Add or remove a member's access group.
Verify webhook signatures with the signing secret
When a webhook has a secret, Mateflow signs each request with HMAC-SHA256 so your server can check that it came from Mateflow and wasn't changed (signature verification). Each request carries two headers:
X-Mateflow-Timestamp: when the request was sent, in Unix seconds.X-Mateflow-Signature:sha256=followed by the hex-encoded signature.
To verify a request on your server:
- Read the raw request body exactly as received, before parsing the JSON.
- Build the signed string: the
X-Mateflow-Timestampvalue, a period (.), then the raw body. - Compute an HMAC-SHA256 of that string, keyed with your secret, and hex-encode it.
- Compare it with the part of
X-Mateflow-Signatureaftersha256=, using a constant-time comparison. Reject the request if they differ. - Optionally, reject requests with a timestamp more than a few minutes old, to block replays.
During a transition period, requests also carry the secret itself in an X-Webhook-Secret header. Verify the signature rather than relying on that header.
Requests from an automation rule's Trigger webhook action work differently: they aren't signed, and the rule's secret is sent as-is in the X-Webhook-Secret header. See Automate tasks with rules.
After you save, the secret is hidden. To keep it, leave the field blank when you edit the webhook. To rotate it, generate a new one and update your server at the same time.
Test, pause, edit, or delete a webhook
In the webhook's Actions menu:
- Test Webhook sends a test request to your endpoint.
- Disable stops deliveries without deleting the webhook; Enable turns it back on.
- Edit changes its name, URL, secret, or events.
- Delete removes the webhook and all of its delivery logs. This can't be undone.
The list shows each webhook's Status, Last Triggered, and Success and Failed counts. A webhook shows an error status when recent deliveries have failed.
Check webhook deliveries and retries
Open the Delivery Logs tab to see each request, its HTTP Status, Duration, and Source. Click Show Details for the full Request Payload and Response Body. Delivery logs are kept for 30 days.
When a delivery fails, Mateflow retries it automatically, up to 3 times. There's no button to resend a delivery yourself. Each attempt gets its own row and a new Delivery ID, while the Event ID stays the same, so rows that share an Event ID are attempts at one event. Deliveries can arrive more than once or out of order, so have your server de-duplicate on the event ID. For payload fields, see the developer documentation at mateflow.com/developers.
Related articles
Was this guide helpful?