Skip to main content
A webhook sends hiring events to a URL you own: a new application, a booked interview, an accepted offer. Use it to post to Slack, update a sheet, or start your own workflow. Nothing to poll.

Add a webhook

Owners and admins manage webhooks in the app under Settings > API > Webhooks. Members can see them and their delivery log, but can’t change them.
  1. Click New webhook.
  2. Enter an https URL.
  3. Keep All events, or pick the events this URL should get.
  4. Click Add webhook and copy the signing secret. It is shown once.
A company can have up to 10 webhooks. Each one has its own URL, its own events, and its own secret, so you can send offers to one system and everything to another. Open a webhook to change its URL or events. That keeps the same secret. Rotate secret issues a new one and shows it once; deliveries sign with it right away. Send test event posts a signed ping to the URL and shows the response.

Events

Pick All events to also get events added later.

The request

Every delivery is a POST with a JSON body:
Events about an application carry the fields above, with custom_fields in the same shape as applications. Some add a little more: feedback.submitted never carries a verdict, since someone else on the panel may not have added theirs yet. feedback.completed comes once nothing is hidden from anyone on the panel, so feedback lists each person’s user_id, name, verdict (strong_no, no, yes, or strong_yes), and ratings on the job’s interview criteria (id, name, rating, which is null for a skipped criterion). Notes are left out; read them with list_feedback. Neither is sent while your company has interview feedback turned off.
Job events send only job_id and job_title. A ping sends webhook_id and company_id. Each request has these headers:

Verify the signature

The signature is an HMAC-SHA256 of the timestamp, a period, and the raw request body, keyed with the webhook’s secret. Compute it over the bytes you received, before parsing the JSON, and compare in constant time. Reject a timestamp more than five minutes from your clock, so an old request can’t be replayed.

Respond and retries

Answer with any 2xx within 10 seconds. Do slow work after you respond. Anything else counts as a failure. Hotfix tries a delivery up to 5 times, waiting 1 minute, 5 minutes, 30 minutes, then 2 hours between tries. After the fifth failure the delivery shows as failed. A test event is not retried. Because of retries, you can get the same delivery more than once. Use X-Hotfix-Delivery to drop repeats. Deliveries can also arrive out of order, so read starts_at and the current state instead of assuming the order you receive them in.

Delivery log

Open a webhook to see its last deliveries: the event, whether it was delivered, the response code, how many tries it took, and the error when it failed.