harkbell

Integrations · Your other software

Signed webhooks and an API, for Make, n8n or your own server

Give Harkbell an address and it posts every booking, callback and call there as it happens, signed so you can prove the post came from Harkbell.

Posts signed events

What it does

  • One address, the events you choose

    The Webhook in Settings → Developers takes an address and a tick box per event. An address set up before the tick boxes existed keeps receiving exactly the three booking events it always did, until you tick more.

  • Signed the way Stripe signs

    Every delivery carries a harkbell-signature header: a timestamp and an HMAC-SHA256 of the timestamp and the body, made with your signing secret. Stripe’s own webhook library verifies it unchanged, and the timestamp stops a recorded delivery being replayed later.

  • Retried when your server has a bad moment

    A 5xx, a 429, a timeout or no answer at all is retried, with a longer pause each time, for about 30 minutes. A 404 or a 401 is not retried, because asking an address that said no again changes nothing. An address subscribed through the API that fails 3 attempts in a row is paused instead — 30 seconds at first, doubling up to an hour — without using up the event’s retries.

  • An API for the rest

    An API key lets your own code subscribe addresses to events, fetch the latest events of a kind, look contacts up, and add contacts and callbacks. The developer reference lists every endpoint and every payload.

  • Only to addresses that are safe to call

    Harkbell posts only to public internet addresses on the standard ports, checks the address again before every delivery, and never follows a redirect with a signed body.

Turning it on

  1. Open Settings → Developers, enter your address under Webhook and press Set up webhook.
  2. Tick the events you want, and copy the signing secret into your receiver.
  3. Press Send test event, and check that your receiver answered and verified the signature.
  4. For Make or n8n, create a webhook trigger in your scenario or workflow and use the address it gives you.
  5. For your own code, create a key under API keys and follow the developer reference.

Every endpoint, every event with an example payload, and how to check a signature are in the developer reference.

What this actually takes

  • An address on the public internet that answers on port 443 or 80.
  • An owner or admin of your Harkbell workspace. The webhook sends customer details wherever it points.
  • Any Harkbell plan, the free one included.

the part nobody else prints

What it will never do

  • Follow a redirect. A signed body is never sent on to an address nobody checked.
  • Post to a private or internal address, or to anything that resolves to one.
  • Include a call’s transcript or recording, or a booking request’s one-tap confirmation link.
  • Promise order or exactly-once delivery. Every event carries an id, so a receiver can ignore one it has already seen.

Questions people ask about this one

How do I check the signature?

Make an HMAC-SHA256 of the timestamp, a full stop and the raw request body with your signing secret, and compare it with v1 in the harkbell-signature header. The developer reference has the code in Node, Python and PHP.

What happens when my server answers 410?

For a subscription made through the API, Harkbell deletes the subscription and stops posting to it, which is how REST hooks are meant to end. For the Webhook in your settings, a 410 is recorded as a failure and not retried, and you switch it off yourself.

Why did a subscription switch itself off?

Its address failed 15 delivery attempts in a row. It shows as Switched off under Connected automations in Settings → Developers, and subscribing the same address to the same event again — turning the Zap or scenario off and on does it — switches it back on. The Webhook in your settings is never switched off automatically.

What does a delivery look like?

A POST with a JSON body: an id, the event’s name, when it happened, your business, and the booking, callback, call, request or contact it is about. The developer reference shows one of each.

Your other software

Hear it before you connect anything.

The free plan has real answered minutes. Put it on your own website, ask it the questions your callers ask, and connect webhooks when you are convinced.