Back to the help center

Integrations

Set up webhooks

Receive consent and scan events with signed webhooks

Available on the Business plan and above. See pricing for what each plan includes.

Receive real-time events (consent updates, scans, etc.) in your systems.

Create a webhook

  1. Go to Webhooks → New Webhook.
  2. Enter your endpoint URL (HTTPS recommended).
  3. Select events to listen for (e.g., consent.updated, scan.completed).
  4. Add a secret if you want to sign requests.
  5. Save and test.

Validate requests

  • We send JSON payloads with event type and data.
  • If you set a secret, verify signatures before processing.
  • Respond with 2xx; we retry on failures with backoff.

Privacy signal audit data

Every consent webhook includes privacy signal fields for compliance:

GPC (Global Privacy Control):

  • gpc.signal_detected: Was a GPC signal present?
  • gpc.honored: Did we apply the opt-out?
  • gpc.consent_source: banner, gpc_auto, or api
  • gpc.region_code: User's jurisdiction (e.g., US-CA)

DNT (Do Not Track):

  • dnt.signal_detected: Was a DNT signal present?
  • dnt.honored: Was the signal honored?

Use these fields to prove compliance with 12+ US state privacy laws that require honoring GPC signals.

Test safely

  • Use a tool like webhook.site or your staging endpoint.
  • Trigger a test event from the webhook detail page if available.

Troubleshooting

  • If you get no events: check endpoint logs/firewalls and confirm it returns 200-level responses.
  • If you see duplicates: process idempotently (use event IDs).
  • Rotate the secret if it’s ever exposed.

Still stuck?

Email [email protected] with your domain and what you tried. Signed-in customers can also open a ticket from the dashboard.