Webhooks

Webhooks

Outbound webhooks let Flow80 push real-time events to your server as your workflows run. Configure them in Settings → Webhooks.

How It Works

  1. 1
    Create a webhook endpoint

    Set up a POST endpoint on your server that accepts JSON.

  2. 2
    Register in Flow80

    Add your URL and select events in Settings → Webhooks.

  3. 3
    We send events

    Flow80 POSTs to your URL whenever matching events occur.

  4. 4
    Verify & respond

    Validate the HMAC-SHA256 signature, process the event, return 2xx.

Available Events

flow.started Fired when a workflow execution begins.
flow.completed Fired when a workflow finishes successfully.
flow.failed Fired when a workflow errors or times out.
flow.step_completed Fired after each individual step finishes.
flow.step_failed Fired when a specific step errors.
webhook.delivered Fired when Flow80 receives an inbound webhook.
webhook.received Fired when an inbound webhook is received and accepted.

Payload Format

Every webhook POST includes this structure:

json
1{2  "event":       "flow.completed",3  "flow_id":     "wf_xxxxxxxxxxxxxxxx",4  "run_id":      "run_yyyyyyyyyyyyyyyy",5  "timestamp":   "2026-04-08T10:23:45Z",6  "payload":     {7    "order_id":        "ORD-12345",8    "status":          "completed",9    "steps_executed":  4,10    "duration_ms":     124311  }12}

Signature Verification

Every outbound webhook includes an X-Flow80-Signature header — the HMAC-SHA256 hex digest of the raw request body, signed with your webhook secret. Always verify server-side.

Never skip verification. Without HMAC verification, any actor who discovers your webhook URL could send fake events to your system.

Verify webhook signature

PHP
1<?php2// Flow80 — verify inbound webhook signature (HMAC-SHA256)3function verify_flow80_signature(4    string $payload,5    string $signature,6    string $secret7): bool {8    $expected = hash_hmac('sha256', $payload, $secret);9    return hash_equals($expected, $signature);10}11 12// In your webhook handler:13$raw_body    = file_get_contents('php://input');14$signature   = $headers['X-Flow80-Signature'] ?? '';15$webhook_secret = 'whsec_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx';16 17if (!verify_flow80_signature($raw_body, $signature, $webhook_secret)) {18    http_response_code(401);19    exit('Invalid signature');20}21 22$data = json_decode($raw_body, true);23// → $data['event'], $data['flow_id'], $data['run_id'], $data['timestamp']

Retry Behavior

If your endpoint doesn't return a 2xx within 10 seconds, Flow80 retries with exponential backoff:

2xxAcknowledged within 10 seconds
4xxNot retried. Fix your request payload.
5xx / timeoutExponential backoff: 30s → 2m → 10m → 1h
Max attempts4 total attempts. Marked as failed after final attempt.

Failed deliveries appear in Settings → Webhooks with error details and the ability to replay individual events.