Skip to main content

How to use Webhooks?

Written by Jerre

Webhooks let your application receive notifications when specific events happen in Snitcher.

When an event fires, Snitcher sends an HTTP POST with a JSON body to an endpoint you control, so you can route identified companies, returning-visitor sessions, and revealed contacts into your own systems in near real time.


Common things customers do with webhooks:

  • Push Snitcher signals into their own database or data pipeline to trigger downstream actions (for example, campaign triggers).

  • Feed other tools like Clay.

  • Connect to email and marketing automation platforms such as ActiveCampaign.

  • Get sales notifications in tools that support webhooks but don't integrate with Snitcher out of the box, including as a workaround when a CRM plan is too limited for a direct integration.

💡 For no-code destinations, you can also use Zapier or one of the ready-made guides linked at the bottom of this article.


Creating a webhook

  1. Go to Settings > Integrations > Webhooks.

  2. Click Create Webhook.

  3. Fill in the details:

    • Name (required): a label so you can identify this webhook later.

    • URL (required): the HTTPS endpoint where you want the payloads delivered. It must be a real, publicly reachable URL (a localhost or internal-only URL will be rejected).

    • Webhook Secret (optional): a secret key used to sign each payload so you can verify it genuinely came from Snitcher. See Verifying the signature below.

🚨 A webhook on its own doesn't send anything yet. You need to connect it to a trigger.


Connecting a webhook to a trigger

A webhook fires when something points at it. There are two ways to do that.

Through an Automation:

  1. Go to Automations and click Create Automation.

  2. Choose the trigger event (for example, New Lead, or a returning visitor's New Session).

  3. Choose the Segment this automation will apply to.

  4. Set the action to Webhook.

  5. Select the webhook you created.

Through the "Send to" action in the Inbox: select a company or contact, choose Send to..., then Send to Webhooks, and pick your webhook from the list.

Sending a company fires a new_lead event; revealing a contact and sending it fires a contacts_revealed event.


Events

Snitcher sends three webhook events:

  • new_lead: an identified company, sent when a company matches an automation's trigger or is sent manually.

  • new_session: a returning visitor's new session, sent when the automation's trigger is a new session.

  • contacts_revealed: a revealed contact.

Which event a webhook receives depends entirely on the trigger you attached to it.

There is no separate event-type selector on the webhook itself.


Payload reference

All payloads are delivered as application/json.

new_lead and new_session

These two share the same structure. Top level:

Field

Description

event

new_lead or new_session

site_id

Your Snitcher site ID

automation_name

Name of the automation that fired it (if any)

segment_name

Name of the matched segment (if any)

subjects[]

List of identified companies

Each entry in subjects[] contains:

Field

Description

id

Company identifier

first_seen, last_seen

Timestamps

total_sessions, total_pageviews, total_time_on_site

Aggregate engagement

unique_pages_visited[]

Pages visited (up to 100)

unique_referers[], unique_campaigns[], unique_visitor_locations[]

Traffic context

tags[]

Tags applied to the company

link

Link to the company in Snitcher

company{}

Company firmographics (see below)

recent_sessions[]

Recent sessions (each with up to 30 pageviews)

company{} includes: name, domain, website, industry, founded_year, employee_range, annual_revenue, total_funding, location, description, phone, geo{}, and profiles{} (crunchbase, linkedin, facebook, twitter, instagram, youtube).

Each entry in recent_sessions[] includes: started_at, source, browser, device_type, operating_system, total_duration, location{}, and pageviews[] (each with url, title, host, path, time_spent, visited_at).


contacts_revealed

Field

Description

event

contacts_revealed

person{}

The revealed person

organisation{}

Their company

person{} includes: uuid, name, first_name, last_name, email, title, headline, linkedin_url, seniority, departments, phone.

organisation{} includes: name, domain, url.


Testing your webhook

On the webhook's Logs page, use Send a sample to deliver a canned payload for any of the three events, so you can confirm your endpoint receives and parses it correctly.

The Logs page records the status, response code, and response body for each delivery attempt, so it's the first place to look when something isn't arriving.


Verifying the signature

If you set a Secret on the webhook, Snitcher signs every request so you can confirm it came from Snitcher and wasn't tampered with.

The signature is an HMAC-SHA256 hash of the raw JSON request body, computed with your secret, and sent in the Signature header.

💡 To verify: compute the same HMAC-SHA256 over the exact raw body bytes you received, using your secret, and compare it to the Signature header. If no secret is set, requests are sent unsigned.


Good to know

  • Deliveries are sent in near real time as events occur.

  • Each delivery attempt times out after 10 seconds. Failed deliveries are retried automatically with exponential backoff, up to 3 attempts total.

  • The endpoint's SSL certificate must be valid; self-signed certificates are rejected.

  • Delivery logs are retained for about 30 days, then cleared automatically.

  • Payload size is capped: up to 100 entries in unique_pages_visited, and up to 30 pageviews per session.

Did this answer your question?