Webhooks explained for business owners (and why your tools need them)
Webhooks are how one tool tells another that something happened. Here's what they are, how they differ from APIs, and what to check before relying on them.
By LEBX Team
Published

On this page
If you've ever looked into connecting two business tools, you've probably seen the word webhook. It sounds technical, but the idea is simple: a webhook is a message one system sends to another the moment something happens.
What is a webhook?
Think of it as a doorbell. Instead of your CRM checking the website every few minutes to ask “any new enquiries?”, the website rings the CRM's doorbell as soon as a form is submitted, and hands over the details.
Technically, it's an HTTP request — usually a POST with a JSON body — sent to a URL you provide. The sending tool decides when to send it (on an event), and your receiving system decides what to do with it.
Webhooks vs APIs

- An API is how you ask a system for something or tell it to do something: “give me this contact”, “send this email”. You make the request when you want.
- A webhook is how a system tells you something happened: “a payment succeeded”, “an email bounced”. It makes the request when the event occurs.
Most real automations use both: a webhook arrives with an event, and your workflow then calls one or more APIs to act on it.
Everyday business examples
- 01
Payment received
Your payment provider sends a webhook → an invoice is created and a welcome email goes out.
- 02
Email bounced
Your email platform sends a webhook → the contact is flagged in the CRM.
- 03
New chat lead
Your messaging inbox sends a webhook → a deal is created in your pipeline.
- 04
Deal won
Your CRM sends a webhook → a project is set up for the delivery team.
Several LEBX products support webhooks for exactly these cases — for example Omni can call webhooks from its automation builder, LEBX Mail sends delivery events like opens, clicks and bounces, and LEBX Desk lists webhooks among its integrations.
Security: verify every webhook
A webhook URL is just a web address. If someone discovers it, they could send fake events. Well-designed webhook senders sign each request with a shared secret so the receiver can check it's genuine. A typical check looks like this:
import { createHmac, timingSafeEqual } from "node:crypto";
export function isValidSignature(rawBody: string, signature: string, secret: string) {
const expected = createHmac("sha256", secret).update(rawBody).digest("hex");
const a = Buffer.from(expected);
const b = Buffer.from(signature);
return a.length === b.length && timingSafeEqual(a, b);
}- Use HTTPS endpoints only.
- Verify signatures (or a secret token) before processing.
- Validate the payload shape — never trust incoming data blindly.
- Keep secrets in environment variables, never in front-end code.
Reliability: plan for failure
Networks fail and services restart. Good webhook handling assumes this:
- Respond quickly. Acknowledge the webhook with a 2xx response, then do heavy work in the background. Many senders time out after a few seconds.
- Expect retries and duplicates. Senders often retry failed deliveries, so the same event may arrive twice. Use the event ID to ignore repeats (this is called idempotency).
- Log everything. Keep a record of received events and their outcome, so you can replay or investigate problems.
- Alert on failures. If processing fails repeatedly, someone should know.
Getting started
List the moments in your business where one tool should immediately tell another something — a payment, a booking, a new lead. Those are your webhook candidates. If you'd like help designing the integrations, see our automation services, or read the lead follow-up guide for a complete worked example.
FAQ
An API is used to request data or trigger actions when you choose. A webhook is sent automatically by a system when an event happens.
They can be, when the receiver uses HTTPS, verifies a signature or secret on each request, and validates the payload before processing it.
- #api integrations
- #webhooks
- #workflow automation



