Zapier ingest and outgoing webhooks
Last verified 2026-07-16
Integrations are workspace scoped. Only workspace admins can create keys, endpoints, tests, or replays. Support impersonation is read only.
Send a contact from Zapier
Where: Settings → API & Integrations
- Create an API key and copy it once. Store it in Zapier as a secret.
- Use Webhooks by Zapier to POST JSON to /api/ingest/contacts.
- Set Authorization to Bearer followed by the workspace API key.
- Include campaignId, an idempotencyKey, and a contact object. Reusing the key returns the original stored event and does not enroll twice.
- Map standard contact fields directly. Map approved custom fields by their stable field keys, not their display labels.
Receive outgoing events
Planned, with no public release date. Outbound webhook delivery remains unavailable until the integration and its delivery safeguards are ready.
Add an HTTPS webhook under API & Integrations and choose the events it may receive. Klosent stores each event before delivery and sends a stable event ID and delivery ID so the receiver can deduplicate retries.
Test delivery validates the saved connection safely and records the result without contacting the destination. Outbound delivery remains unavailable until the integration and its delivery safeguards are ready.
- X-Integration-Event identifies the event type.
- X-Integration-Delivery is stable across automatic retries.
- X-Integration-Timestamp is the Unix signing time.
- X-Integration-Signature is v1= followed by HMAC-SHA256 of timestamp, a period, and the exact request body.
- Campaign completion events include the exact metric window and say when an older campaign required the bounded partial window.
- Return any 2xx status after storing the delivery. Safe rate-limit retries use bounded backoff. Timeouts, network ambiguity, and server errors stop for admin review so a possibly accepted event is not sent twice.
Delivery log and replay
The delivery log shows status and bounded attempt counts without exposing endpoint secrets or message bodies. An admin may replay only a definitively rejected delivery. Replay keeps the same event identity so the receiver can remain idempotent.
A timeout, network ambiguity, server error, or manual-review event is not safe to replay automatically because the receiver may already have accepted it. Reconcile it with the receiving system first. If you cannot confirm the outcome, contact support before taking any further action.