webhook
event
Every registered endpoint receives the event types it subscribed to, as a POST with
three headers:
x-clixcrm-event— the event type, e.g.lead.created.x-clixcrm-delivery— the delivery id, stable across retries. De-duplicate on it.x-clixcrm-signature—sha256=<hex>, an HMAC-SHA256 of the exact raw body keyed
with the endpoint's secret. Compare in constant time; only sent when the endpoint
has a secret.
Answer quickly. Any 2xx is success. Anything else is retried with exponential
backoff (1s, 2s, 4s … capped at 30 minutes) up to six attempts, after which the
delivery is marked dead and shown as failed in the CRM.
200Any 2xx marks the delivery as delivered. The body is ignored.
