Last updated
Outgoing webhooks: your office's events reach your systems as they happen
Outgoing webhooks are a feature through which EvaCore sends your office's events, such as a new lead, a viewing or a reservation, to an HTTPS address in your other system, with a signature for verification. Up to five endpoints per office, set up by the owner only. It is included in Agency and needs a developer to receive the requests.
Included
Create your workspaceWhat is it?
The «Connect your systems» (الربط مع أنظمتكم) page lets the owner define endpoints that receive JSON events of nine types. Each endpoint has a name, its chosen events and its own signing secret, and every request carries a signature your system verifies. What was sent is kept in a delivery log you can read, and failures are resent automatically on a fixed schedule.
Who is it for?
- An office with a CRM, ERP or reporting dashboard that wants new-lead data to reach it without manual entry.
- A developer that wants unit reservations or deposit payments to reach its accounting system.
- A manager who wants another system to react when a lead's status changes or a viewing is booked.
- An office with a developer or integrator who needs a clear contract for events and signing.
What problem does it solve?
- Data is entered twice: once in EvaCore and once in the other system.
- Polling for changes is slow and misses whatever it did not catch.
- There is no way to be sure a request really came from EvaCore.
- When your system goes down, you do not know which events were lost.
How it works, step by step
- Open «Integrations», then «Connect your systems». The page is for the owner only.
- Click to add an endpoint: enter a name (up to 80 characters) and the full HTTPS URL, and tick the events it receives from the nine: new lead, lead status changed, lead assigned, viewing booked, viewing cancelled, unit held, deposit paid, unit sold, reservation ended unsold.
- Copy the signing secret that starts with whsec_, which is shown only once. If you lose it, change it with «Rotate secret».
- Put the secret in your system and add the verification function: read the X-EvaCore-Signature header holding the time t and the signature v1, and compute an HMAC with SHA-256 over the time and the raw body exactly as received. The guide at the bottom of the page has a ready Node.js example, and the accepted tolerance is 5 minutes.
- Click «Send test» to send a test event immediately and see the response before waiting for a real one.
- When a real event happens, a POST request is sent with a body holding the id, type, time and data, plus the X-EvaCore-Event and X-EvaCore-Delivery headers. Due events are sent by a background job that runs regularly.
- Watch the delivery log: each event with its status (delivered, retrying, stopped), HTTP code, attempt count and next retry.
- If delivery fails, retries are scheduled after 1 minute, then 5 minutes, 30 minutes, 2 hours, 6 hours and 24 hours. After that the event stops and you can click «Resend» from the log.
- If the endpoint fails for three days in a row without a success, it is switched off and the owner is notified in the app, and on WhatsApp when a number is on file. Fix the endpoint, then switch it back on.
What is included
- Up to 5 endpoints per office, each with its own events and secret, and each can be paused without deleting it.
- Nine event types in three groups: leads, viewings, reservations and deposits.
- An HMAC SHA-256 signature in the X-EvaCore-Signature header, with a secret shown once that can be rotated.
- «Send test», a delivery log of the latest 100 deliveries, and «Resend».
- Six retries at growing intervals up to 24 hours.
- Automatic switch-off of a failing endpoint after three days, with an owner notification.
Limits and fair use
- The URL must start with https on port 443 or 8443, accepts no username or password inside the URL, and no internal or private addresses.
- Delivery is at least once, not exactly once. You may receive the same event more than once, and the X-EvaCore-Delivery id stays the same on every retry so you can skip repeats.
- A successful response is any 2xx within 10 seconds. A redirect counts as a failure and is not followed.
- Events are sent to you only. The feature does not accept commands from your system into EvaCore.
- You need a developer or integrator to write the receiving endpoint and the signature check.
- The feature is for the owner only. Reservation and deposit events are produced only for offices that have the reservations module on.
Price and what others bill you
| Item | Price | Billed by |
|---|---|---|
| Outgoing webhooks | Included | EvaCore |
Frequently asked questions
- Which events can be sent?
- Nine: new lead, lead status changed, lead assigned, viewing booked, viewing cancelled, unit held, deposit paid, unit sold, and reservation ended unsold. You choose what each endpoint receives.
- How does my system know a request came from EvaCore?
- By verifying the signature: your system computes an HMAC with SHA-256 over the time and the raw body using the endpoint's secret and compares it to the value in the X-EvaCore-Signature header, rejecting any request older than 5 minutes.
- What if my system is down for hours?
- Retries are scheduled after 1 minute, then 5 minutes, 30 minutes, 2 hours, 6 hours and 24 hours, after which the event stops and you can resend it from the delivery log.
- Can I pause an endpoint without deleting it?
- Yes, with the switch beside the endpoint. Nothing is sent while it is paused, and its log and setup remain.
- What if the signing secret leaks?
- Click «Rotate secret» and the old secret stops at once, and every later request and every retry is signed with the new secret.