Skip to content
ProjectBrain Docs
Work in progress: these docs are being written and change often.

Webhooks

Send a signed request to your own server when a routing template step runs, and check on your server that it came from ProjectBrain.

GAOwnerExecutiveLast updated 5 October 2026
WhoPeople with webhooks.manage choose where webhooks may go. People who edit routing templates add the step.Roles

A routing template can include a webhook step. When the step runs on a task, ProjectBrain sends an HTTP request to a URL you choose, for example to tell another system that a task was assigned.

ProjectBrain only sends webhooks to hostnames your organization has approved.

  1. Go to Settings > Webhooks (Webhook Allowlist).
  2. Add the hostname, such as hooks.example.com, with a description.
  3. Copy the signing secret and store it on your server.

The hostname must match exactly. A webhook to any other host fails, and the task’s activity shows why.

In a routing template, add a step with the webhook action and set:

  • URL, which can include placeholders such as {{task.title}}
  • Method: POST (the default), PUT or PATCH
  • Optional headers and body. With no body, the task is sent as JSON.

The workflow carries on whether the webhook succeeds or not. Each attempt shows on the task’s activity.

Every request carries an X-Signature header. It is the HMAC-SHA256 of the raw request body, using that hostname’s secret, written as hex.

To check it on your server:

  1. Read the raw body exactly as received, before parsing it.
  2. Compute HMAC-SHA256 of the body with your secret.
  3. Compare it to X-Signature using a constant-time comparison. Reject the request if it does not match.

Rotate a secret from Settings > Webhooks if you think it has leaked. For seven days after a rotation, requests also carry X-Signature-Previous, signed with the old secret. Accept a request if either header matches, update your server to the new secret, then rely on X-Signature only.

  • A 2xx response counts as delivered.
  • A 4xx response counts as failed and is not retried.
  • A 5xx response, a timeout or a network error is retried a few times with growing gaps, then given up.

Respond quickly. A request that takes longer than 30 seconds is treated as failed.