Overview
Webhooks let Sendora push events to your server the moment they happen, instead of polling the API. Register an HTTPS endpoint, choose which events you care about, and Sendora will deliver a signed POST request within seconds.Event catalog
Registering an endpoint
secret immediately. It is sensitive and should not be committed or returned to your frontend.
Payload shape
Every webhook POST contains the event-specific fields plus theevent_type field:
Event-specific payloads
call.completed
call.completed
meeting.booked
meeting.booked
booked_via is either "voice_agent" (AI booked during a call) or "operator" (manual booking in Unibox).campaign.finished
campaign.finished
lead.enriched
lead.enriched
Verifying signatures
Sendora signs every delivery with HMAC-SHA256 using the endpoint’ssecret. Always verify the signature before processing the payload.
Sendora signs every delivery with HMAC-SHA256. Always verify before processing.
X-Sendora-Signature header as sha256=<hex>. Reject anything that doesn’t match.
Here’s how to wire it into a request handler:
Delivery flow
Delivery and retries
- Sendora expects your endpoint to return
2xxwithin 30 seconds - If it times out or returns a non-2xx, Sendora retries after 10 seconds and 100 seconds (3 attempts total)
- After 5 failures, the delivery is marked
failed, check the delivery log
Viewing delivery history
Testing an endpoint
Send a syntheticcall.completed event to verify your endpoint is reachable:
call.completed test payload.
Best practices
- Acknowledge fast, process async, return
200immediately, then handle the event in a queue/worker - Make handlers idempotent, the same delivery may be attempted more than once; use a stable event-specific identifier when one is present, or deduplicate using your own delivery ledger
- Always verify signatures, reject anything with an invalid or missing signature header
- Monitor the delivery log, set up alerts if failure rate climbs