Set up automated data push, configure event triggers, and connect your workflow tools.

Eventact Webhooks

An Eventact webhook sends data to external systems when something happens or changes in Eventact. Instead of requiring third-party software to check Eventact for updates (known as polling via API), it pushes details to a web address (URL) you configure in the back office.

For example, when an attendee completes registration, Eventact sends their registration details to the other system.

Webhook vs. API

With a polling API, the external system repeatedly checks Eventact for new registrations. With a webhook, Eventact delivers each record as soon as it is created.

API (your system asks):
Your system ── "Any new registrations?" ──> Eventact
Your system <── "No."                    ─── Eventact
Your system ── "Any new registrations?" ──> Eventact
Your system <── "Yes, 1."                ─── Eventact

Webhook (Eventact sends):
Attendee registers ──> Eventact ── HTTP POST ──> Your destination URL

Webhooks are faster and use fewer requests than polling. After a webhook triggers, the receiving system can query the Eventact API for additional data or actions. Webhooks and the API work well together.

What You Can Use It For

Supported Triggers

Trigger Event Name When It Fires
Registration created registration.created A new registration is submitted. This includes registrations waiting for admin approval or offline payment.

Edits to existing registrations and cancellations trigger different event names, which this article does not cover.

Duplicates: An Eventact admin can manually resend a registration webhook from the back office, so your endpoint may receive the same registration more than once. Use data.registrationId to skip registrations you've already processed.

Company Webhooks vs. Project Webhooks

Level Where to Configure Scope
Company Settings › Integrations › Webhooks Fires for every project in your account, including future ones. Use this to sync all attendee data into a single CRM or data warehouse.
Project Inside the project: Registration › Webhooks Fires for that project only. Use this for single-event workflows, such as a dedicated Slack channel or a conference-specific Zapier flow.

If both a project webhook and a company webhook are active, both fire. If they point to the same URL, that endpoint receives two deliveries per registration.

Setting Up a Webhook

  1. Open Webhooks at the company or project level and click Add webhook.
  2. Enter a name you'll recognize later (for example, HubSpot - Production or Zapier - Attendee Sync).
  3. Enter the destination URL. It must begin with https:// and be accessible from the public internet.
  4. Under Triggers, select Registration created.
  5. Set Status to Enabled and click Save.
The Eventact back office Webhooks page: a Zapier - Attendee Sync webhook listed as Enabled, with its details panel showing the URL, trigger, call count, and signing secret, and the menu open with Send ping, Send sample registration.created, New secret, and Delete
A project webhook in the back office: details, signing secret, and the ⋮ menu with the test and secret options

After saving, the webhook is assigned a signing secret that begins with whsec_. Click the eye icon to view it or the copy icon to copy it. You will need this secret to verify payload authenticity.

Propagation Note: Configuration updates take effect for new registrations within approximately 10 minutes.

Testing a Webhook

There are two testing options, both available in the webhook's ⋮ menu (click the webhook row, then click ⋮). Send ping is also available as a separate button at the bottom of the webhook configuration panel.

Test What It Sends Intended Use
Send ping A ping event with no registrant fields Confirms that your URL is reachable, returns a 2xx response within 10 seconds, and verifies signatures.
Send sample registration.created A complete registration.created payload with all standard fields populated Gives Zapier, Make, or custom receivers a full data schema to map fields from without needing a dummy registration.

Both tests are signed like real deliveries.

Connecting Zapier or Make

Zapier

  1. In Zapier, create a Zap with Webhooks by Zapier › Catch Hook as the trigger.
  2. Copy the URL Zapier provides.
  3. In Eventact, add a webhook with that URL and save.
  4. Click the webhook row, open the ⋮ menu, and select Send sample registration.created. Zapier will capture the complete sample registration.
  5. Map the parsed fields to downstream actions in your Zap.

Make (Integromat)

  1. In Make, add a Webhooks › Custom webhook module and generate an address.
  2. Copy the address.
  3. In Eventact, add a webhook with that address and save.
  4. Click the webhook row, open the ⋮ menu, and select Send sample registration.created. Make reads the sample and generates the data structure.
  5. Map the fields into your scenario.

Important: Do not use Send ping for initial setup in Zapier or Make. A ping does not include registrant fields, so there is no schema to map downstream.

Custom form questions and secondary tickets are not included in the webhook payload. To access them, add an HTTP step in your workflow to query the Eventact API using data.registrationId.

Webhook Payload Reference

Each delivery is an HTTPS POST request carrying a JSON body:

{
  "id": "6f1c2a9e-1b7d-4a53-9a51-0d2f7c9e1a10",
  "event": "registration.created",
  "createdAt": "2026-10-08T10:00:01Z",
  "companyId": 12,
  "projectId": 3456,
  "data": {
    "registrationId": 487215,
    "contactId": 312908,
    "formId": 10842,
    "formName": "VIP & Speaker Registration",
    "projectName": "Hyperion Nexus Live",
    "registeredAt": "2026-10-08T09:59:59Z",
    "status": "submitted",
    "ticket": "VIP Pass",
    "firstName": "Nikos",
    "lastName": "Andrews",
    "fullName": "Nikos Andrews",
    "organization": "Quantix Semiconductors",
    "jobTitle": "Director of AI Infrastructure",
    "email": "nikos.andrews@example.com",
    "phone": "+306944123456",
    "price": 450.0,
    "currency": "EUR"
  }
}

Body Properties

Property Type Description
id UUID Unique ID for this delivery, matching the webhook-id header.
event String registration.created, or ping for a ping test.
createdAt ISO 8601 string When the webhook was sent (UTC).
companyId Integer Your Eventact account ID.
projectId Integer The project where the registration occurred.
data.registrationId Integer Registration ID. Use it to identify duplicate deliveries.
data.contactId Integer Contact ID, shared across all projects in your account.
data.formId Integer ID of the registration form.
data.formName String Name of the registration form.
data.projectName String Project name.
data.registeredAt ISO 8601 string When the registrant submitted the form (UTC).
data.status String submitted (complete) or pending (waiting for approval or offline payment).
data.ticket String or null Internal name of the first ticket on the registration, as set in the admin. If there are several tickets, only the first is included. If there is no ticket, it's null.
data.firstName String First name.
data.lastName String Last name.
data.fullName String Full name.
data.organization String Company or organization.
data.jobTitle String Job title.
data.email String Email address.
data.phone String Phone number in international format.
data.price Decimal Total amount for the registration, including tickets not listed in data.ticket.
data.currency String ISO currency code (for example EUR, USD, ILS).

Custom form questions are not included. To retrieve them or the complete ticket list, query the Eventact API using data.registrationId.

Delivery Headers

Eventact formats delivery headers in accordance with the Standard Webhooks specification:

Header Description
webhook-id Unique ID of this delivery, matching id in the body.
webhook-timestamp Integer Unix timestamp (in seconds) of when the delivery was sent.
webhook-signature The signature string in the format v1,{base64_signature}.
X-Eventact-Event The event name, matching event in the body.

Verifying the Signature

Eventact signs every delivery according to the Standard Webhooks specification. Verifying the signature confirms the request came from Eventact and was not altered in transit.

The simplest approach is using an official standardwebhooks package (available for Node.js, Python, Go, Ruby, and Java). Pass it your signing secret, the raw request body, and the request headers.

Body Integrity Warning: Always verify against the raw, unparsed request body. If your application framework parses the JSON before verification, re-serializing it may change byte ordering and whitespace, which can cause verification to fail.

Node.js (Express)

const express = require('express');
const { Webhook } = require('standardwebhooks');

const app = express();
const wh = new Webhook(process.env.EVENTACT_WEBHOOK_SECRET); // whsec_...

// Use express.raw() on the webhook route so req.body is a raw Buffer
app.post('/eventact/webhook', express.raw({ type: 'application/json' }), (req, res) => {
  try {
    wh.verify(req.body, req.headers);
  } catch (err) {
    return res.status(400).send('Invalid signature');
  }

  const payload = JSON.parse(req.body.toString('utf8'));
  // Handle payload...
  res.sendStatus(200);
});

Python (Flask)

import os
import json
from flask import Flask, request
from standardwebhooks.webhooks import Webhook

app = Flask(__name__)
wh = Webhook(os.environ["EVENTACT_WEBHOOK_SECRET"])  # whsec_...

@app.post("/eventact/webhook")
def eventact_webhook():
    raw_body = request.get_data()

    try:
        wh.verify(raw_body, dict(request.headers))
    except Exception:
        return "Invalid signature", 400

    payload = json.loads(raw_body.decode('utf-8'))
    # Handle payload...
    return "", 200

Without a Library

  1. Strip the whsec_ prefix from the signing secret and base64-decode the remaining string. That produces your HMAC key bytes.
  2. Construct the signed string: {webhook-id}.{webhook-timestamp}.{raw body}.
  3. Compute an HMAC-SHA256 hash of that string using the key bytes, and base64-encode the result.
  4. The webhook-signature header holds space-separated signatures in the form v1,{signature}. Accept the delivery if any signature matches using a constant-time comparison.
  5. Reject requests where webhook-timestamp differs by more than 5 minutes from your server time to prevent replay attacks.

Replacing a Signing Secret

If your signing secret is exposed, open the webhook's ⋮ menu and select New secret.

The new secret can take 10 minutes or longer to take effect. During that transition window, deliveries may still be signed with the previous secret. Have your endpoint temporarily support both: verify with the new secret first, and if that fails, try the old secret. Remove the old secret once incoming deliveries pass with the new one.

Delivery Rules

Handling Missed Events: Because there are no automated retries, temporary server downtime can result in missed deliveries. To recover missing records, an administrator can manually resend webhooks from the Eventact back office, or your system can poll the Eventact REST API on a schedule.

Monitoring & Troubleshooting

The Webhooks list shows each webhook's current status and the timestamp of its most recent delivery. Select a webhook to review delivery counts and recent error responses, such as 404 Not Found or Timeout after 10 seconds. A warning badge appears when recent calls fail and clears automatically after the next successful delivery.

If your endpoint is not receiving webhook calls:

Read more