Integrations
Webhook event catalog
Event types, payloads, and signature tips
Available on the Business plan and above. See pricing for what each plan includes.
Know what events we send and how they’re structured.
Common events
consent.updated: A user changed consent; payload includes categories granted/denied, timestamp.scan.completed: A scan finished; payload has domain, counts, summary.webhook.test: Test event from the dashboard.
Payload structure (example)
{
"id": "evt_123",
"type": "consent.updated",
"created_at": "2025-01-10T12:00:00Z",
"data": {
"domain": "example.com",
"choices": {
"analytics": true,
"marketing": false,
"preferences": true
},
"gpc": {
"signal_detected": true,
"honored": true,
"consent_source": "gpc_auto",
"region_code": "US-CA"
}
}
}Global Privacy Control (GPC) fields
Every consent webhook includes GPC data for audit compliance:
| Field | Description |
|---|---|
gpc.signal_detected | Whether browser sent GPC signal |
gpc.honored | Whether the opt-out was applied |
gpc.consent_source | How consent was obtained: banner, gpc_auto, api |
gpc.region_code | Jurisdiction code (e.g., US-CA, EU) |
Use these fields to prove you honored GPC signals for 12+ US states including California, Colorado, Connecticut, Texas, Oregon, and more.
Do Not Track (DNT) fields
We also capture the legacy DNT signal:
| Field | Description |
|---|---|
dnt.signal_detected | Whether browser sent DNT signal |
dnt.honored | Whether the signal was honored |
Note: DNT is not legally binding but shows good faith privacy practices.
Security
- Use the signing secret (if enabled) to verify signatures.
- Respond 2xx; we retry failures with backoff.
- Process idempotently using
idto avoid duplicates.
Testing
- Use the Send test button from the webhook detail page.
- Point to a staging endpoint or webhook.site when developing.
Still stuck?
Email [email protected] with your domain and what you tried. Signed-in customers can also open a ticket from the dashboard.