Skip to main content
Webhooks send an HTTP notification when an event occurs in Bold. Use them so a management system, analytics tool, internal automation, or intermediary service can react without continuously polling the API.
Webhooks complement the API. Use the API to query or correct the final state, and use webhooks to learn that something changed.

What a subscription configures

Workflow

1

Create the receiver

Publish a URL that accepts JSON requests and responds promptly. Bold accepts http and https; use https in production.
2

Create the subscription

Register endpoint, eventName, and eventVersion in Bold.
3

Process the data received

Save the event identifier to prevent duplicates, and use the API if you need more data.
4

Return a successful response

Respond with a 2xx code when you accept the event for processing.

Subscription endpoints

These operations require the App.Admin permission.
You can also review subscriptions and deliveries in Webhooks in the Control panel.

Notification history

Bold stores notifications and their delivery attempts so you can diagnose failures.
Do not perform heavy work while responding to the webhook HTTP request. Queue the event, return 2xx, and process it in the background.

Webhook signature

Bold signs the serialized JSON body with HMAC-SHA256 and sends the signature as lowercase hexadecimal in the X-HMAC-Signature header.
Verify the signature against the unmodified body. If you parse and serialize the JSON again before verification, the signature may not match.