Set up a Webhook trigger
The Webhook node starts the flow from an outside system's POST. Copy the address shown in the panel, ending in a secret part; a Secret Key adds a signature check.
A Webhook trigger starts the flow from an HTTP POST sent by an outside system. A flow carries one trigger only, so the Webhook node takes the place of the Başlangıç node and keeps the connections leaving it. The address shown in the panel ends in a random secret part; treat it like a password. The incoming JSON is written to the variable named in Payload Değişkeni. A webhook flow has no customer. Message nodes are sent to nobody, and a menu that waits for a reply ends the run as an error. Every run appears in Akış Logları.
Before you start
- A flow open in the editor; the Webhook node sits in the Tetikleyici group of the Node'lar palette.
- An outside system that can POST: a CRM, an online store or an automation tool.
- A saved flow switched to Aktif; a call to an inactive flow gets 404.
- A valid JSON body of at most 256 KB; an empty or broken body gets 400, a larger body 413.
- If you fill in Secret Key, a sender that can compute and add the X-Chatinbox-Signature header.
Step by step
These screens sit inside the Intent AI section. Sign in, open Intent AI; the menu names below are in that section's left menu.
Drop the Webhook node on the canvas
Open the Node'lar palette on the left of the editor. Drag Webhook out of the Tetikleyici group onto the canvas. It replaces the current trigger and keeps the outgoing connections.
Copy the address and name the payload variable
The Webhook URL field in the right panel shows the address. Its last part is a random secret part the panel generated. Press the copy button. Type the name your flow will use in Payload Değişkeni; the default is webhook_payload. An invalid name still writes the data to webhook_payload.
Set a Secret Key if you wish
Type a key into Secret Key (Opsiyonel). Every request must then carry the header X-Chatinbox-Signature: sha256=<signature>. The signature is the HMAC-SHA256 of the raw body with this key, in lowercase hex. A request without it, or with a wrong one, gets 401.
Save, switch to Aktif and send a test call
Save with Ctrl+S and switch the flow to Aktif from the toolbar. Send one POST request with a JSON body from the outside system; the answer is 200. Open the Akış Logları panel from the toolbar. If a row detail is open, go back to the list with the back arrow in the panel, then press Yenile. The new row at the top shows a Tamamlandı badge; if you see Hata, check the problems below. Click the row to open its Node izleme list.
Generate a new address if it leaks
Press Yeni adres üret in the panel and save with Ctrl+S. The old address stops working the moment you save and gets 404. Pass the new address to the sending system.
Result checkIf it did not work
Check these
- A 404 means the address is missing or wrong, the flow is inactive, or its trigger is not the Webhook. All of these return the same 404. Copy the address from the panel again. Switch the flow to Aktif and check that the Webhook node is on the canvas.
- A 400 means an empty or broken JSON body; a 413 means the body is over 256 KB. Check that the sending system posts valid JSON.
- A 401 means Secret Key is set but the signature is missing or wrong. Compute the signature over the raw body with the key shown in the panel; the header must start with sha256=.
- A 503 means the system could not take the request at that moment. A 429 means more than 120 requests a minute came from the same IP address. In both cases wait a short while and send again.
- A row marked Hata in Akış Logları can mean the flow reached a node that waits for a customer reply. A webhook flow has no customer to answer. Remove waiting nodes such as a menu from this flow.
- Anyone who can open the flow sees the address and the Secret Key in the panel. Give both only to the system that should trigger the flow; if they leak, press Yeni adres üret and save.
Does this step look different in your panel?
We can review the screen and exact error text together.
This guide was checked against the product UI and code inventory on 4 October 2026.
