İçeriğe geç

Endpoint'ler

Webhooks

Subscribe a URL to workspace events. This is what the Make instant triggers call when a scenario is turned on and off.

Webhook’lar nasıl çalışır

Webhooks, workspace'te bir şey olduğunda URL'nize bir olay gönderir: yeni bir kişi, bir randevu, ödenmiş bir sipariş, biten bir arama. Her teslimat imzalıdır, böylece Entagl'dan geldiğini doğrulayabilirsiniz.

Bir endpoint kurun

POST /webhooks ile bir endpoint oluşturun. Aşağıdaki listeden (veya GET /events ile) olay türlerini seçin ya da contact.* veya * gibi bir joker karakter kullanın. Yanıt, imzalama secret değerini bir kez içerir: saklayın. Make için Entagl uygulaması, Entagl trigger'ı olan bir scenario açıldığında bunu sizin için yapar ve kapatıldığında endpoint'i siler.

İstek
curl -X POST "https://api.entagl.com/api/v1/webhooks" \
  -H "Authorization: Bearer ai_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://example.com/entagl/webhooks",
    "events": ["contact.created", "booking.*"],
    "description": "CRM sync"
  }'

Uygulamada Kanallar → Webhooks sayfasından kurabileceğiniz webhook orijinal biçimi kullanır: gövde { event, workspace_id, occurred_at, data } şeklindedir ve X-Entagl-Signature, sha256= ile ham gövdenin HMAC-SHA256 değerinin birleşimidir. Aşağıdaki her şey API ile oluşturulan endpoint'leri anlatır.

Olay biçimi

Her teslimat, JSON bir olay içeren bir POST'tur. type ne olduğunu söyler, data o tür için ayrıntıları taşır (olay listesine bakın). actor olayı kimin yarattığını (ai, human, customer, system, api, import veya provider), source.connection_id ise hangi kimlik bilgisinin kullanıldığını söyler; böylece bir entegrasyon kendi değişikliklerini yok sayabilir. Güncelleme olayları ayrıca değişen alan adlarını içeren changes taşır.

contact.created
{
  "id": "evt_5c1f0a9e7b2d4e3f8a6c0b1d2e3f4a5b",
  "object": "event",
  "type": "contact.created",
  "api_version": "2026-10-01",
  "occurred_at": "2026-10-01T14:32:11.482Z",
  "created_at": "2026-10-01T14:32:11.482Z",
  "workspace_id": "00000000-0000-0000-0000-000000000000",
  "actor": {
    "type": "api",
    "id": "user_9f2c1a"
  },
  "resource": {
    "type": "contact",
    "id": "6789"
  },
  "source": {
    "connection_id": "apikey:42",
    "via": "api"
  },
  "data": {
    "contact_id": 6789,
    "name": "Jane Doe",
    "first_name": "Jane",
    "last_name": "Doe",
    "phone": "+15551234567",
    "email": "jane@example.com",
    "channel": "instagram",
    "tags": [
      "vip",
      "botox"
    ],
    "stage": {
      "funnel_id": 3,
      "stage_id": 14,
      "stage_name": "Qualified"
    },
    "assigned_to_user_id": "user_9f2c1a",
    "language": "en",
    "custom_fields": {
      "budget": "500-1000",
      "preferred_branch": "Downtown"
    },
    "created_at": "2026-09-28T10:02:44.000Z",
    "updated_at": "2026-10-01T14:32:11.482Z"
  },
  "changes": null
}
  • Content-Typeapplication/json
  • User-AgentEntagl-Webhooks/2.0
  • X-Entagl-Signatureİmza, aşağıya bakın.
  • X-Entagl-Event-IdOlay ID'si. Yinelenenleri atlamak için kullanın.
  • X-Entagl-Event-TypeOlay türü, örn. contact.created.
  • X-Entagl-Delivery-Attemptİlk denemede 1, sonra 2, 3 …

İmzayı doğrulayın

X-Entagl-Signature header'ı t=1767225600,v1=5257a869… gibi görünür. t, Unix saniyesi olarak gönderim zamanıdır. Her v1, endpoint secret'ınızla üretilen {t}.{raw body} metninin hex biçiminde HMAC-SHA256 değeridir. Kendiniz hesaplayın ve sabit zamanlı karşılaştırın. t, saatinizden 5 dakikadan fazla uzaksa isteği reddedin. Secret yenilemesinden sonra 24 saat boyunca iki v1 değeri bulunur: biri eşleşirse isteği kabul edin.

Node.js (Express)
import crypto from 'node:crypto';
import express from 'express';

const app = express();
// The secret returned once by POST /api/v1/webhooks (or by rotate-secret).
const SECRET = process.env.ENTAGL_WEBHOOK_SECRET;

// Read the RAW body: the signature covers the exact bytes Entagl sent.
app.post('/entagl/webhooks', express.raw({ type: 'application/json' }), (req, res) => {
  const rawBody = req.body.toString('utf8');
  if (!verifyEntaglSignature(req.get('X-Entagl-Signature') || '', rawBody, SECRET)) {
    return res.status(400).send('invalid signature');
  }
  const event = JSON.parse(rawBody);
  // Deliveries can repeat: skip an event.id you have already handled.
  console.log(event.type, event.id);
  res.sendStatus(200); // any 2xx within 10 seconds counts as delivered
});

function verifyEntaglSignature(header, rawBody, secret, toleranceSeconds = 300) {
  const parts = header.split(',').map((p) => p.trim());
  const t = Number(parts.find((p) => p.startsWith('t='))?.slice(2));
  if (!Number.isFinite(t) || Math.abs(Date.now() / 1000 - t) > toleranceSeconds) return false;
  const expected = crypto.createHmac('sha256', secret).update(`${t}.${rawBody}`).digest('hex');
  return parts
    .filter((p) => p.startsWith('v1='))
    .some((p) => {
      const got = p.slice(3);
      return got.length === expected.length &&
        crypto.timingSafeEqual(Buffer.from(got), Buffer.from(expected));
    });
}

app.listen(3000);

Teslimat ve tekrar denemeler

  • 10 saniye içinde herhangi bir 2xx durumuyla yanıt verin. Yönlendirmeler izlenmez.
  • Başka her şey başarısız denemedir. Entagl 30 saniye, 2 dakika, 10 dakika, 1 saat, 6 saat ve 24 saat sonra tekrar dener, sonra teslimatı başarısız olarak işaretler (toplam 7 deneme).
  • 410 Gone tekrar denemeleri hemen durdurur ve endpoint'i devre dışı bırakır.
  • 72 saat boyunca başarısız olmaya devam eden bir endpoint devre dışı bırakılır ve workspace sahibine bildirim gider. PATCH /webhooks/:id ve "status": "active" ile tekrar açın.
  • Bir teslimat birden fazla kez gelebilir ve olaylar sıra dışı gelebilir. Yinelenenleri atlamak için olay ID'sini kullanın.
  • GET /webhooks/:id/deliveries son 30 günün denemelerini gösterir; POST …/redeliver birini yeniden gönderir.

Gizlilik

Varsayılan olarak olaylar, müşterilerin yazdıklarını (mesaj metni, transkriptler, özetler, notlar) ve iletişim bilgilerini (adlar, telefonlar, e-postalar, kullanıcı adları) içermez. Olay listesi her olay için bu alanları gösterir. Bunları almak için endpoint'te include_content ve/veya include_contact_details ayarlayın. Yalnızca workspace sahibi veya admin bunları açabilir. HIPAA workspace'lerinde ayarlar ne olursa olsun asla gönderilmez. Özel bir alan dışarıda bırakıldığında changes yine adını listeler ama eski değerini asla göstermez.

Olay listesi

Entagl'ın şu anda gönderdiği her olay türü. message.received ve message.sent yüksek hacimlidir: joker karakter bunları asla içermez, bu yüzden adlarıyla listeleyin. GET /events aynı kataloğu JSON olarak döndürür.

Contacts (11)

contact.createdContact created

Fires when a new contact is added: a first message from someone new, a manual add, an import or the API.

Kişi bilgisi alanları:namefirst_namelast_namephoneemailcustom_fields

contact.updatedContact updated

Fires when any contact field or custom field changes. The envelope "changes" lists the changed fields and their previous values.

Kişi bilgisi alanları:namefirst_namelast_namephoneemailcustom_fields

contact.deletedContact deleted

Fires when a contact is deleted. Carries ids only.

contact.tag_addedContact tag added

Fires when one or more tags are added to a contact.

contact.tag_removedContact tag removed

Fires when one or more tags are removed from a contact.

contact.stage_changedLifecycle stage changed

Fires when a contact moves to another funnel stage, or the stage is removed.

contact.assignedContact owner changed

Fires when a contact is assigned to a team member or unassigned.

contact.lead_capturedLead captured

Fires when the AI (or a form) marks a contact as a lead, with a short summary of what they want.

İçerik alanları:summary

Kişi bilgisi alanları:namephoneemail

contact.mergedContacts merged

Fires when two contacts are merged into one. The secondary contact id now redirects to the primary.

contact.opted_outContact opted out

Fires when a contact is marked do-not-contact or opts out of marketing messages.

note.createdContact note added

Fires when a team member adds a note to a contact.

İçerik alanları:body

Conversations (7)

conversation.createdConversation opened

Fires when a new conversation starts on any channel.

conversation.reopenedConversation reopened

Fires when a closed conversation is opened again, by a new customer message or a team member.

conversation.closedConversation closed

Fires when a conversation is closed by a team member, the API or auto-close, with the closing note if any.

İçerik alanları:closing_note_text

conversation.assignedConversation assignee changed

Fires when a conversation is assigned to a team member or unassigned.

conversation.ai_pausedAI paused on a conversation

Fires when AI replies are paused on a conversation (team member takeover, handover, spam, schedule or API).

conversation.ai_resumedAI resumed on a conversation

Fires when AI replies are switched back on for a conversation.

conversation.comment_createdConversation comment added

Fires when a team member (or the API) adds an internal comment to a conversation. Customers never see comments.

İçerik alanları:body

Messages (3)

message.receivedIncoming message
Yüksek hacim: adıyla abone olun

Fires for every message a customer sends, on any channel. High volume — subscribe only if you need every message.

İçerik alanları:text

message.sentOutgoing message
Yüksek hacim: adıyla abone olun

Fires for every message sent to a customer: AI replies, team replies, campaigns and automations.

İçerik alanları:text

message.send_failedMessage failed to send

Fires when a message to a customer could not be delivered by the channel.

Handovers (2)

handover.requestedHandover requested

Fires when the AI hands a conversation to a human (customer asked for a person, complaint, or a question it could not answer).

İçerik alanları:summary

Kişi bilgisi alanları:customer_namecustomer_phone

handover.resolvedHandover resolved

Fires when a team member (or auto-resolve) marks a handover as handled.

AI (3)

conversation.followup_sentFollow-up sent

Fires when the AI sends an automatic follow-up to a customer who went quiet.

ai_turn.failedAI reply failed

Fires when the AI could not produce a reply for a customer message (a fallback message may have been sent instead).

message_feedback.submittedAI reply rated

Fires when a team member gives thumbs up or down to an AI reply.

İçerik alanları:comment

Bookings (6)

booking.createdBooking created

Fires when an appointment is created for a customer.

İçerik alanları:conversation_summarydocuments

Kişi bilgisi alanları:customer_namecustomer_phone

booking.documents.addedBooking documents added

Fires when a customer shares a document or photo in a conversation after their booking was created. Delivers only the new file(s).

İçerik alanları:documents

Kişi bilgisi alanları:customer_namecustomer_phone

booking.updatedBooking updated

Fires when any booking detail changes (time, service, duration, location, notes). The envelope "changes" lists what changed.

Kişi bilgisi alanları:customer_namecustomer_phone

booking.rescheduledBooking rescheduled

Fires when a booking moves to a new date or time.

Kişi bilgisi alanları:customer_namecustomer_phone

booking.cancelledBooking cancelled

Fires when a booking is cancelled by the customer (through the AI), a team member, or the API.

Kişi bilgisi alanları:customer_namecustomer_phone

booking.status_changedBooking status changed

Fires when a booking status changes, e.g. confirmed, completed or no-show.

Kişi bilgisi alanları:customer_namecustomer_phone

Reminders (4)

reminder.createdReminder created

Fires when a reminder is created.

İçerik alanları:titlenote

reminder.firedReminder due

Fires when a reminder becomes due and the assignees are notified.

İçerik alanları:titlenote

reminder.closedReminder closed

Fires when a reminder is marked done.

İçerik alanları:titlenote

appointment_reminder.sentAppointment reminder sent

Fires when an automatic appointment reminder (WhatsApp template or SMS) is sent to a customer.

Orders (6)

order.createdOrder created

Fires when an order is created by the AI, a team member, a store sync or the API.

Kişi bilgisi alanları:customer_namecustomer_phone

order.updatedOrder updated

Fires when any order detail or item changes. The envelope "changes" lists what changed.

Kişi bilgisi alanları:customer_namecustomer_phone

order.status_changedOrder status changed

Fires when an order status changes (for example confirmed, shipped, delivered).

Kişi bilgisi alanları:customer_namecustomer_phone

order.paidOrder paid

Fires when an order is marked as paid.

Kişi bilgisi alanları:customer_namecustomer_phone

order.cancelledOrder cancelled

Fires when an order is cancelled.

Kişi bilgisi alanları:customer_namecustomer_phone

order.payment_proof_uploadedPayment proof uploaded

Fires when a customer (through the AI) or a team member attaches a payment receipt to an order.

Products (3)

product.createdProduct created

Fires when a product is added to the catalog.

product.updatedProduct updated

Fires when a product changes (price, stock, details).

product.deletedProduct deleted

Fires when a product is removed from the catalog.

Calls (3)

call.endedCall ended

Fires after every AI phone or WhatsApp call, with outcome and (opt-in) summary and transcript.

İçerik alanları:summarytranscript

Kişi bilgisi alanları:from_numberto_number

call.missedMissed call

Fires when an incoming call was not answered or an outgoing call got no answer.

İçerik alanları:summarytranscript

Kişi bilgisi alanları:from_numberto_number

call.voicemail_receivedVoicemail received

Fires when a caller leaves a voicemail.

İçerik alanları:transcript_text

Kişi bilgisi alanları:from_number

Campaigns (3)

campaign.completedCampaign finished sending

Fires when a broadcast campaign finished sending to all recipients.

campaign_recipient.repliedCampaign reply

Fires when a recipient replies to a campaign message.

campaign_recipient.failedCampaign message failed

Fires when a campaign message could not be delivered to a recipient.

Forms (1)

form.submittedForm submitted

Fires when a customer submits a form (website widget, hosted link or in-chat intake).

İçerik alanları:fields

Account (3)

channel.disconnectedChannel disconnected

Fires when a channel stops working (token expired, access removed) or is disconnected.

channel.reconnectedChannel healthy again

Fires when a previously failing channel works again.

credits.threshold_reachedCredits running low

Fires when credit usage crosses 80%, 100% or 120% of the plan allowance.

Workspace (3)

tag.createdTag created

Fires when a tag is added to the workspace tag list.

tag.updatedTag updated

Fires when a workspace tag is renamed or recolored.

tag.deletedTag deleted

Fires when a workspace tag is deleted (it is removed from every contact).

Yollar temel URL'ye göredir. Her kart, çağrının gerektirdiği izni ve her parametreyi türü ve sınırlarıyla listeler.

GET
/webhooks

List webhook endpoints.

İzin: integrations
Sayfalı
POST
/webhooks

Create a webhook endpoint. The signing secret is returned once, in this response.

İzin: integrations

JSON gövdesi

  • urlzorunlustring (URL)

    https:// URL that receives events, up to 2,048 characters. Private and internal addresses are refused (422 unsafe_url).

  • eventszorunluarray of strings

    1–100 event types from GET /events, "<prefix>.*" (e.g. "contact.*") or "*". Wildcards never include message.received and message.sent; list those explicitly.

  • descriptionisteğe bağlıstring

    Up to 200 characters.

  • filtersisteğe bağlıobject

    Optional narrowing: channels (array of channel names, up to 20), actor_types (array, up to 7), sources (object of event type → source keys), ignore_own_changes (boolean — skip events caused by this same connection; on by default for connector-created endpoints).

  • include_contentisteğe bağlıboolean

    Include message text, transcripts and notes. Owner or admin only; refused on HIPAA workspaces.

  • include_contact_detailsisteğe bağlıboolean

    Include names, phones, emails and handles. Owner or admin only; refused on HIPAA workspaces.

  • created_viaisteğe bağlıenum

    Which tool created the endpoint.

    İzin verilen değerler:apimakezapiern8n

  • A workspace can have up to 100 endpoints (409 endpoint_limit_reached).
GET
/webhooks/:id

Retrieve a webhook endpoint with its status and last delivery result.

İzin: integrations

Yol parametreleri

  • idzorunlustring

    Endpoint ID (starts with "we_").

PATCH
/webhooks/:id

Update an endpoint, or pause and re-activate it.

İzin: integrations

Yol parametreleri

  • idzorunlustring

    Endpoint ID.

JSON gövdesi

  • urlisteğe bağlıstring (URL)

    New receiving URL.

  • eventsisteğe bağlıarray of strings

    New event list.

  • descriptionisteğe bağlıstring | null

    Up to 200 characters.

  • filtersisteğe bağlıobject

    Optional narrowing: channels (array of channel names, up to 20), actor_types (array, up to 7), sources (object of event type → source keys), ignore_own_changes (boolean — skip events caused by this same connection; on by default for connector-created endpoints).

  • include_contentisteğe bağlıboolean

    Owner or admin only to turn on.

  • include_contact_detailsisteğe bağlıboolean

    Owner or admin only to turn on.

  • statusisteğe bağlıenum

    Re-activating resets the failure count.

    İzin verilen değerler:activepaused

  • On an endpoint that includes content or contact details, only an owner or admin can change url, events or filters.
DELETE
/webhooks/:id

Delete an endpoint (a Make trigger calls this when its scenario is turned off).

İzin: integrations

Yol parametreleri

  • idzorunlustring

    Endpoint ID.

POST
/webhooks/:id/rotate-secret

Issue a new signing secret. The previous secret keeps signing deliveries for 24 hours.

İzin: integrations

Yol parametreleri

  • idzorunlustring

    Endpoint ID.

POST
/webhooks/:id/test

Send a signed sample event to the endpoint now and return the result (delivered, status, error, duration_ms).

İzin: integrations

Yol parametreleri

  • idzorunlustring

    Endpoint ID.

JSON gövdesi

  • eventisteğe bağlıstring

    Event type to sample. Defaults to the endpoint's first non-wildcard event, else a generic "webhook.test" event.

GET
/webhooks/:id/deliveries

Recent delivery attempts, newest first. Deliveries are kept for 30 days.

İzin: integrations
Sayfalı

Yol parametreleri

  • idzorunlustring

    Endpoint ID.

POST
/webhooks/:id/deliveries/:deliveryId/redeliver

Queue a delivery to be sent again. Answers 202.

İzin: integrations

Yol parametreleri

  • idzorunlustring

    Endpoint ID.

  • deliveryIdzorunluinteger

    Delivery ID from the deliveries list.