Skip to main content
Webhooks let your systems react to activity in your Zapnito community. You register a URL for an event, and Zapnito sends a JSON payload to that URL whenever the event happens.
Webhooks are called REST hooks in the API. The subscription endpoints use the rest_hooks path.

How it works

1

Choose an event

Pick the event you want to hear about from the events list.
2

Create a subscription

Send a POST request to the event’s subscriptions endpoint with the URL to notify. The response contains the subscription id.
3

Receive payloads

Zapnito sends a JSON payload to your URL each time the event happens.
4

Delete the subscription

Send a DELETE request with the subscription id when you no longer need notifications.

Authentication

Every subscription request needs your API token in the Authorization header:
To have Zapnito authenticate itself to your endpoint, pass an authorization_token when you create the subscription. Zapnito then sends it in the Authorization header of each request to your URL, in the format Token token=YOUR_ENDPOINT_TOKEN.

Subscription endpoints

All events use the same two endpoints, where EVENT is the API name from the events list: Replace https://your-community.zapnito.com with your community’s domain. Creating a subscription returns 201 Created with the subscription id. Deleting one returns 204 No Content, or 404 Not Found if no subscription matches the ID.

Request headers

Each payload Zapnito sends to your URL includes these headers.
Headers sent to your URL
  • X-Zapnito-Hostname is the hostname of the Zapnito community that sent the event.
  • Authorization is only sent if you set an authorization_token when you created the subscription.

Payload conventions

Payload formats aren’t yet consistent across events. The details below come from the example payload on each event page, so check the example for the event you’re handling and parse values defensively.

Timestamps

IDs

If you handle more than one event, convert IDs to a single type before you compare or store them.

Booleans

The confirmed field in the User registered and User updated payloads is the string "true", not a boolean. The room flags in the content payloads (open, secret and private) are booleans.

Personal data

User-related payloads include names and email addresses. The User deleted payload still contains the deleted user’s name, email address and professional registration number. Treat these payloads as personal data when you log or store them.

Events