Webhooks let your application receive notifications when specific events happen in Snitcher.
When an event fires, Snitcher sends an HTTP POST with a JSON body to an endpoint you control, so you can route identified companies, returning-visitor sessions, and revealed contacts into your own systems in near real time.
Common things customers do with webhooks:
Push Snitcher signals into their own database or data pipeline to trigger downstream actions (for example, campaign triggers).
Feed other tools like Clay.
Connect to email and marketing automation platforms such as ActiveCampaign.
Get sales notifications in tools that support webhooks but don't integrate with Snitcher out of the box, including as a workaround when a CRM plan is too limited for a direct integration.
đĄ For no-code destinations, you can also use Zapier or one of the ready-made guides linked at the bottom of this article.
Creating a webhook
Go to Settings > Integrations > Webhooks.
Click Create Webhook.
Fill in the details:
Name (required): a label so you can identify this webhook later.
URL (required): the HTTPS endpoint where you want the payloads delivered. It must be a real, publicly reachable URL (a localhost or internal-only URL will be rejected).
Webhook Secret (optional): a secret key used to sign each payload so you can verify it genuinely came from Snitcher. See Verifying the signature below.
đ¨ A webhook on its own doesn't send anything yet. You need to connect it to a trigger.
Connecting a webhook to a trigger
A webhook fires when something points at it. There are two ways to do that.
Through an Automation:
Go to Automations and click Create Automation.
Choose the trigger event (for example, New Lead, or a returning visitor's New Session).
Choose the Segment this automation will apply to.
Set the action to Webhook.
Select the webhook you created.
Through the "Send to" action in the Inbox: select a company or contact, choose Send to..., then Send to Webhooks, and pick your webhook from the list.
Sending a company fires a new_lead event; revealing a contact and sending it fires a contacts_revealed event.
Events
Snitcher sends three webhook events:
new_lead: an identified company, sent when a company matches an automation's trigger or is sent manually.new_session: a returning visitor's new session, sent when the automation's trigger is a new session.contacts_revealed: a revealed contact.
Which event a webhook receives depends entirely on the trigger you attached to it.
There is no separate event-type selector on the webhook itself.
Payload reference
All payloads are delivered as application/json.
new_lead and new_session
These two share the same structure. Top level:
Field | Description |
|
|
| Your Snitcher site ID |
| Name of the automation that fired it (if any) |
| Name of the matched segment (if any) |
| List of identified companies |
Each entry in subjects[] contains:
Field | Description |
| Company identifier |
| Timestamps |
| Aggregate engagement |
| Pages visited (up to 100) |
| Traffic context |
| Tags applied to the company |
| Link to the company in Snitcher |
| Company firmographics (see below) |
| Recent sessions (each with up to 30 pageviews) |
company{} includes: name, domain, website, industry, founded_year, employee_range, annual_revenue, total_funding, location, description, phone, geo{}, and profiles{} (crunchbase, linkedin, facebook, twitter, instagram, youtube).
Each entry in recent_sessions[] includes: started_at, source, browser, device_type, operating_system, total_duration, location{}, and pageviews[] (each with url, title, host, path, time_spent, visited_at).
contacts_revealed
Field | Description |
|
|
| The revealed person |
| Their company |
person{} includes: uuid, name, first_name, last_name, email, title, headline, linkedin_url, seniority, departments, phone.
organisation{} includes: name, domain, url.
Testing your webhook
On the webhook's Logs page, use Send a sample to deliver a canned payload for any of the three events, so you can confirm your endpoint receives and parses it correctly.
The Logs page records the status, response code, and response body for each delivery attempt, so it's the first place to look when something isn't arriving.
Verifying the signature
If you set a Secret on the webhook, Snitcher signs every request so you can confirm it came from Snitcher and wasn't tampered with.
The signature is an HMAC-SHA256 hash of the raw JSON request body, computed with your secret, and sent in the Signature header.
đĄ To verify: compute the same HMAC-SHA256 over the exact raw body bytes you received, using your secret, and compare it to the Signature header. If no secret is set, requests are sent unsigned.
Good to know
Deliveries are sent in near real time as events occur.
Each delivery attempt times out after 10 seconds. Failed deliveries are retried automatically with exponential backoff, up to 3 attempts total.
The endpoint's SSL certificate must be valid; self-signed certificates are rejected.
Delivery logs are retained for about 30 days, then cleared automatically.
Payload size is capped: up to 100 entries in
unique_pages_visited, and up to 30pageviewsper session.






