Skip to main content
This is the technical reference for sending events to a Hive incoming webhook. Every request must be signed with the webhook’s secret; Hive rejects anything it cannot verify.

Endpoint

Copy the full URL from Hive when you create the webhook. The workspace is identified from the URL alone, so nothing in the body can redirect an event to another workspace.

Request

string
required
application/json
string
required
Lowercase hexadecimal HMAC-SHA256 of the exact raw request body bytes, keyed with the webhook’s signing secret. No prefix (send 3f1a…, not sha256=3f1a…).
JSON
required
UTF-8 JSON, at most 64 KB (65,536 bytes). Any JSON is accepted; bodies that match the proposal contract (proposal.created, proposal.won, client.created) are mapped natively. See Incoming webhooks for the field rules.
Sign the bytes you actually send. Re-serialising JSON after signing — changing key order, spacing or encoding — changes the bytes and the signature will not match.

Response

Signature verification happens before the body is parsed, and uses a constant-time comparison.

Deduplication and retries

Hive deduplicates on the SHA-256 of the raw body, per webhook. Retrying the same bytes after a timeout is safe: you get 202 with "deduplicated": true, and the event is processed once. To send two genuinely separate events with the same content, make the bodies differ — for example with a distinct eventId.

Examples

In a Zapier “Code by Zapier” or Make custom-code step, use the Node.js or Python sample to compute the signature, then send it with a webhook/HTTP step using the same body string.

Security notes

  • Treat the signing secret like a password. Store it in your automation tool’s secret storage, never in source control.
  • Hive stores only a sealed copy of the secret and cannot show it again. To rotate, create a new webhook, switch your sender to it, then delete the old one.
  • Event content is treated as untrusted input: every field is bounded and validated before it reaches the Business Brain.

Incoming webhooks

Create a webhook and the event contract.

Developer overview

Everything you can build against.