October 8, 2026 | 9 min read
Set up automated data push, configure event triggers, and connect your workflow tools.
An Eventact webhook sends data to external systems when something happens or changes in Eventact. Instead of requiring third-party software to check Eventact for updates (known as polling via API), it pushes details to a web address (URL) you configure in the back office.
For example, when an attendee completes registration, Eventact sends their registration details to the other system.
With a polling API, the external system repeatedly checks Eventact for new registrations. With a webhook, Eventact delivers each record as soon as it is created.
API (your system asks):
Your system ── "Any new registrations?" ──> Eventact
Your system <── "No." ─── Eventact
Your system ── "Any new registrations?" ──> Eventact
Your system <── "Yes, 1." ─── Eventact
Webhook (Eventact sends):
Attendee registers ──> Eventact ── HTTP POST ──> Your destination URL
Webhooks are faster and use fewer requests than polling. After a webhook triggers, the receiving system can query the Eventact API for additional data or actions. Webhooks and the API work well together.
| Trigger | Event Name | When It Fires |
|---|---|---|
| Registration created | registration.created |
A new registration is submitted. This includes registrations waiting for admin approval or offline payment. |
Edits to existing registrations and cancellations trigger different event names, which this article does not cover.
Duplicates: An Eventact admin can manually resend a registration webhook from the back office, so your endpoint may receive the same registration more than once. Use
data.registrationIdto skip registrations you've already processed.
| Level | Where to Configure | Scope |
|---|---|---|
| Company | Settings › Integrations › Webhooks | Fires for every project in your account, including future ones. Use this to sync all attendee data into a single CRM or data warehouse. |
| Project | Inside the project: Registration › Webhooks | Fires for that project only. Use this for single-event workflows, such as a dedicated Slack channel or a conference-specific Zapier flow. |
If both a project webhook and a company webhook are active, both fire. If they point to the same URL, that endpoint receives two deliveries per registration.
https:// and be accessible from the public internet.
After saving, the webhook is assigned a signing secret that begins with whsec_. Click the eye
icon to view it or the copy icon to copy it. You will need this secret to verify payload authenticity.
Propagation Note: Configuration updates take effect for new registrations within approximately 10 minutes.
There are two testing options, both available in the webhook's ⋮ menu (click the webhook row, then click ⋮). Send ping is also available as a separate button at the bottom of the webhook configuration panel.
| Test | What It Sends | Intended Use |
|---|---|---|
| Send ping | A ping event with no registrant fields |
Confirms that your URL is reachable, returns a 2xx response within 10 seconds, and verifies signatures. |
| Send sample registration.created | A complete registration.created payload with all standard fields populated |
Gives Zapier, Make, or custom receivers a full data schema to map fields from without needing a dummy registration. |
Both tests are signed like real deliveries.
Important: Do not use Send ping for initial setup in Zapier or Make. A ping does not include registrant fields, so there is no schema to map downstream.
Custom form questions and secondary tickets are not included in the webhook payload. To access them, add an HTTP step in your workflow to query the Eventact API using
data.registrationId.
Each delivery is an HTTPS POST request carrying a JSON body:
{
"id": "6f1c2a9e-1b7d-4a53-9a51-0d2f7c9e1a10",
"event": "registration.created",
"createdAt": "2026-10-08T10:00:01Z",
"companyId": 12,
"projectId": 3456,
"data": {
"registrationId": 487215,
"contactId": 312908,
"formId": 10842,
"formName": "VIP & Speaker Registration",
"projectName": "Hyperion Nexus Live",
"registeredAt": "2026-10-08T09:59:59Z",
"status": "submitted",
"ticket": "VIP Pass",
"firstName": "Nikos",
"lastName": "Andrews",
"fullName": "Nikos Andrews",
"organization": "Quantix Semiconductors",
"jobTitle": "Director of AI Infrastructure",
"email": "nikos.andrews@example.com",
"phone": "+306944123456",
"price": 450.0,
"currency": "EUR"
}
}
| Property | Type | Description |
|---|---|---|
id |
UUID | Unique ID for this delivery, matching the webhook-id header. |
event |
String | registration.created, or ping for a ping test. |
createdAt |
ISO 8601 string | When the webhook was sent (UTC). |
companyId |
Integer | Your Eventact account ID. |
projectId |
Integer | The project where the registration occurred. |
data.registrationId |
Integer | Registration ID. Use it to identify duplicate deliveries. |
data.contactId |
Integer | Contact ID, shared across all projects in your account. |
data.formId |
Integer | ID of the registration form. |
data.formName |
String | Name of the registration form. |
data.projectName |
String | Project name. |
data.registeredAt |
ISO 8601 string | When the registrant submitted the form (UTC). |
data.status |
String | submitted (complete) or pending (waiting for approval or offline payment). |
data.ticket |
String or null |
Internal name of the first ticket on the registration, as set in the admin. If there are several tickets, only
the first is included. If there is no ticket, it's null.
|
data.firstName |
String | First name. |
data.lastName |
String | Last name. |
data.fullName |
String | Full name. |
data.organization |
String | Company or organization. |
data.jobTitle |
String | Job title. |
data.email |
String | Email address. |
data.phone |
String | Phone number in international format. |
data.price |
Decimal | Total amount for the registration, including tickets not listed in data.ticket. |
data.currency |
String | ISO currency code (for example EUR, USD, ILS). |
Custom form questions are not included. To retrieve them or the complete ticket list, query the
Eventact API using data.registrationId.
Eventact formats delivery headers in accordance with the Standard Webhooks specification:
| Header | Description |
|---|---|
webhook-id |
Unique ID of this delivery, matching id in the body. |
webhook-timestamp |
Integer Unix timestamp (in seconds) of when the delivery was sent. |
webhook-signature |
The signature string in the format v1,{base64_signature}. |
X-Eventact-Event |
The event name, matching event in the body. |
Eventact signs every delivery according to the Standard Webhooks specification. Verifying the signature confirms the request came from Eventact and was not altered in transit.
The simplest approach is using an official standardwebhooks package (available for Node.js, Python, Go, Ruby,
and Java). Pass it your signing secret, the raw request body, and the request headers.
Body Integrity Warning: Always verify against the raw, unparsed request body. If your application framework parses the JSON before verification, re-serializing it may change byte ordering and whitespace, which can cause verification to fail.
const express = require('express');
const { Webhook } = require('standardwebhooks');
const app = express();
const wh = new Webhook(process.env.EVENTACT_WEBHOOK_SECRET); // whsec_...
// Use express.raw() on the webhook route so req.body is a raw Buffer
app.post('/eventact/webhook', express.raw({ type: 'application/json' }), (req, res) => {
try {
wh.verify(req.body, req.headers);
} catch (err) {
return res.status(400).send('Invalid signature');
}
const payload = JSON.parse(req.body.toString('utf8'));
// Handle payload...
res.sendStatus(200);
});
import os
import json
from flask import Flask, request
from standardwebhooks.webhooks import Webhook
app = Flask(__name__)
wh = Webhook(os.environ["EVENTACT_WEBHOOK_SECRET"]) # whsec_...
@app.post("/eventact/webhook")
def eventact_webhook():
raw_body = request.get_data()
try:
wh.verify(raw_body, dict(request.headers))
except Exception:
return "Invalid signature", 400
payload = json.loads(raw_body.decode('utf-8'))
# Handle payload...
return "", 200
whsec_ prefix from the signing secret and base64-decode the remaining string. That produces your
HMAC key bytes.
{webhook-id}.{webhook-timestamp}.{raw body}.webhook-signature header holds space-separated signatures in the form v1,{signature}.
Accept the delivery if any signature matches using a constant-time comparison.
webhook-timestamp differs by more than 5 minutes from your server time to prevent
replay attacks.
If your signing secret is exposed, open the webhook's ⋮ menu and select New secret.
The new secret can take 10 minutes or longer to take effect. During that transition window, deliveries may still be signed with the previous secret. Have your endpoint temporarily support both: verify with the new secret first, and if that fails, try the old secret. Remove the old secret once incoming deliveries pass with the new one.
localhost, 127.0.0.1,
10.x.x.x, 192.168.x.x) are rejected.
Handling Missed Events: Because there are no automated retries, temporary server downtime can result in missed deliveries. To recover missing records, an administrator can manually resend webhooks from the Eventact back office, or your system can poll the Eventact REST API on a schedule.
The Webhooks list shows each webhook's current status and the timestamp of its most recent delivery. Select a webhook to review delivery counts and recent error responses, such as 404 Not Found or Timeout after 10 seconds. A warning badge appears when recent calls fail and clears automatically after the next successful delivery.
If your endpoint is not receiving webhook calls: