Developer & API

Inbound webhooks that check every delivery before it becomes a lead

Inbound webhooks are how ad platforms push new leads into DigiPix Flow the moment someone submits a form, and each one is verified, stored once and processed with retries so a bad minute on either side does not cost you an enquiry. For systems of your own, the lead API does the same job with an API key.

  • A signature or key checked on every delivery
  • Repeat deliveries recognised, never doubled
  • Failed events retried, then replayable
An example of DigiPix Flow's outbound webhooks settings for an operations endpoint, with its events, a delivery log and the signed headers of the latest delivery. A won deal adds a deal.won delivery as pending, the endpoint answers 503 and the delivery is retried a minute later and delivered with a 200 and a verified signature, and a lead.created delivery that was dead-lettered yesterday is replayed and delivered.
most retries for an event that fails
5
lead per provider event, however often it arrives
1
deliveries a minute accepted on each workspace webhook URL
600

What pushes into DigiPix Flow

  • Meta Lead AdsFacebook and Instagram forms, signed by Meta
  • Google Ads lead formsYour URL plus a key you choose
  • WhatsApp repliesMessages and delivery statuses on your number
  • Website form postsSigned with the form's own secret
  • Lead APIYour own systems, with an API key
  • Audit entryA record of every delivery received
THE PROBLEM

Where receiving leads by webhook goes wrong

See how it's fixed
  1. A URL anyone could post to

    A webhook address is just a link. If it is pasted into the wrong dashboard or leaks in a screenshot, anyone can send fake leads to it, and a receiver that checks nothing will hand them straight to your sales team.

  2. The same lead, delivered three times

    Ad platforms retry when they do not hear back quickly. A receiver that does not recognise a repeat turns one enquiry into three records, and three reps end up calling the same person within the hour.

  3. A failure nobody can see or fix

    A lead arrives while something downstream is having a bad minute and the processing fails. With no record of the delivery and no way to run it again, the enquiry simply disappears, and nobody finds out until the buyer complains.

RECEIVERS

A webhook to the CRM for each lead source that pushes

Meta Lead Ads deliver to DigiPix Flow's own endpoint once you connect with your Meta login, so there is no URL to copy. For Google Ads lead forms, the connector shows your workspace's webhook URL and asks for a key; put the same two on your lead form and every submission is posted straight in. Replies on your connected WhatsApp number arrive by webhook too. IndiaMART is different: its enquiries are collected every five minutes rather than pushed.

  • Meta Lead Ads, connected with a Meta login
  • Google Ads lead forms, with a URL and a key you choose
  • WhatsApp messages and delivery statuses on your number
  • IndiaMART collected every five minutes instead
Explore Google Ads lead forms
An example of the DigiPix Flow Capture hub: Meta Lead Ads, Google Ads lead forms, IndiaMART, website forms, the lead API and CSV import listed as sources, each with its connection status and the number of new leads it brought in today.
VERIFICATION

Every delivery proves where it came from

Each receiver checks a delivery before it is accepted. Meta's requests must carry a valid signature made with the app secret. A Google Ads delivery must name your workspace's URL and carry the exact key you set, compared in a way that gives nothing away to someone guessing. A request that fails is refused with an error, and a body that is not valid JSON is turned away rather than stored.

  • Meta deliveries checked against their signature
  • Google Ads deliveries checked against your key
  • Unknown URLs and failed checks refused
  • Workspace webhook URLs capped at 600 deliveries a minute
An example of report access in DigiPix Flow: the same pipeline report totals ₹6.4 lakh for a sales rep who sees only their own deals, ₹21.3 lakh for a team lead and ₹48.6 lakh for an admin; separate permissions to view, edit and export reports by role; and audit log entries for an export and a new schedule.
ONE EVENT, ONE LEAD

Retries from the sender never become extra leads

Every accepted delivery is stored once, keyed on the sender's own event id, such as Google's lead id. When the same event arrives again because the platform retried, DigiPix Flow answers that it already has it and creates nothing new. The lead that is created then goes through your duplicate checks, so a person who fills in two different forms is flagged for review too.

  • Each event stored once per sender and connection
  • A repeat delivery answered as a duplicate
  • Google's test deliveries accepted for setup checks
  • New leads still checked against your existing ones
Explore duplicate management
An example of DigiPix Flow's duplicate review: a new Meta lead matches an existing website lead on email exactly and on phone once the numbers are normalised, with options to merge the records while keeping both histories or keep them separate, and a similar-looking lead with the same company flagged for a person to review.
RETRIES

Processing that tries again before it gives up

A stored event is handed to a background worker, so the sender gets its answer quickly and the slower work happens afterwards. If processing fails for a reason that may pass, it is tried again after one minute, then five, fifteen, thirty and sixty, up to the number of attempts your workspace allows. An event that still fails is set aside as dead-lettered, and one that can never succeed is marked failed at once.

  • Answered first, processed in the background
  • Retries after 1, 5, 15, 30 and 60 minutes
  • Your own limit on attempts, up to five
  • Dead-lettered events kept, not discarded
An example of an import error report from DigiPix Flow opened as a spreadsheet: contacts-import-errors-c41d7e92.csv with 28 rows, each giving the row number, whether it was skipped or failed, an error code and a plain reason such as a record with this email already exists or a missing name, email and phone, next to the name, email and phone that were uploaded.
REPLAY

Webhook replay for the events that did not make it

Failed and dead-lettered lead events appear in the Capture hub with a Retry button, and each connector with a webhook has a Replay last event action. A replay asks for a reason, needs the right permission and only runs when your workspace allows replays. Anything that already became a lead cannot be retried, so a replay never creates a second copy.

  • Retry failed lead events from the Capture hub
  • Replay the last failed event from a connector
  • A reason and a permission behind every replay
  • Processed events refused, so no second lead
An example of the import and export job history in DigiPix Flow: jobs for leads, contacts, deals and companies that are queued, running, completed, partial or failed, each with rows succeeded and rows with problems, one weekly scheduled export, and a contacts import selected with 1,236 rows imported and 28 with problems, a Download error report button and a Re-run button.
SIGNING & ROTATION

Rotate once, and every inbound URL changes

Your workspace has one inbound signing secret, shown a single time and stored only as a hash. Rotating it from Settings also issues new inbound URLs for every connector that uses one, so a URL that has leaked stops working straight away. Update the Google Ads lead form with its new URL and deliveries resume. Each rotation is written to your audit log, as is every delivery received.

  • A workspace secret shown once, kept as a hash
  • Rotation re-issues every inbound URL
  • Old URLs refused as soon as you rotate
  • Rotations and deliveries recorded in the audit log
Explore the audit log
An example of DigiPix Flow's audit trail filtered to approvals: Neha Patil changed the approval rules, Kavya Iyer requested approval for PROP-00012, Amit Mehta reassigned it to Deepak Kulkarni, Deepak approved it, and Sneha Nair cancelled a request for PROP-00018. The selected decision shows who decided, when, the decision and the comment left with it.
HOW IT WORKS

From a new connector to your first pushed lead, in five steps

  1. STEP 01

    Connect the source

    Sign in to Meta, or open the Google Ads lead form connector and set a key.

  2. STEP 02

    Paste the URL

    Copy your workspace's webhook URL and key into the lead form's settings.

  3. STEP 03

    Send test data

    Press Send test data in Google Ads and watch the connector confirm it arrived.

  4. STEP 04

    Let leads flow

    Each delivery is verified, stored once and turned into a lead.

  5. STEP 05

    Recover failures

    Retry or replay anything that failed, with a reason on record.

THE DIFFERENCE

Inbound webhooks vs copying leads by hand

What it coversCopying leads from ad dashboards by handDigiPix Flow
How leads arriveDownloaded from each dashboard when someone remembersPosted to DigiPix Flow as each form is submitted
Trusting the sourceWhatever is in the downloaded fileA signature or key checked on every delivery
RepeatsThe same lead pasted in twiceRecognised by the sender's event id
When processing failsNobody knows a lead was missedRetried, then set aside for replay
Recovering a leadSearch the dashboard and hope it is still thereRetry from the Capture hub with one click
A leaked linkNothing to changeRotate and every inbound URL is replaced
EvidenceNoneEvery delivery and rotation in the audit log

Inbound webhook questions, answered

What are inbound webhooks in DigiPix Flow?

They are the receivers that let other platforms push events into your workspace: Meta Lead Ads and Google Ads lead forms post new leads, and your connected WhatsApp number posts replies and delivery statuses. Each receiver checks the delivery, stores it once and processes it in the background.

Can any system post JSON to a DigiPix Flow webhook URL?

No. Each inbound URL belongs to a specific provider and checks that provider's signature or key, so there is no general URL that accepts any body. To send leads from a system of your own, use the lead API with an API key, or post to a website form's signed endpoint.

How is this different from the lead API?

Inbound webhooks receive what a platform such as Meta or Google sends in its own format. The lead API is the door for your own code: you send a lead with a Bearer key and an Idempotency-Key header. Both feed the same intake, with the same duplicate checks and assignment rules.

What happens if Google sends the same lead twice?

Nothing new is created. Google's lead id is stored with the first delivery, and any repeat is answered as a duplicate. Google's test deliveries all share a placeholder id, so they are told apart by their content instead, and you can send test data more than once while setting up.

What if processing fails?

The event is retried after one, five, fifteen, thirty and sixty minutes, up to the attempts your workspace allows. If it still fails it is dead-lettered and kept. Failed lead events show in the Capture hub with a Retry button, and connectors offer Replay last event.

Who can replay a webhook event?

People whose role includes permission to replay webhook events, and only while Allow webhook replay is switched on in Settings. Every replay needs a reason, and only failed or dead-lettered events can be replayed.

Does IndiaMART use a webhook?

No. DigiPix Flow collects IndiaMART enquiries every five minutes using your CRM key, which is as often as IndiaMART allows. Those enquiries then go through the same intake as webhook leads.

What do we do if a webhook URL leaks?

Rotate the inbound signing secret in Settings. That issues new inbound URLs at once and the old ones stop working, so copy the new URL into your Google Ads lead form. The new secret is shown once and recorded in the audit log.

Should we use inbound or outbound webhooks?

They work in opposite directions. Inbound webhooks bring leads and messages into DigiPix Flow. Outbound webhooks send signed events from DigiPix Flow to your endpoint when leads, contacts, companies or deals change.

Something we haven't covered? Talk to an expert

Let your ad platforms deliver leads straight to your team

Talk to an expert — bring your Meta and Google Ads lead forms, and see a test lead arrive verified and stored once.

  • A real person, not a bot
  • Bring your lead forms
  • See a test lead arrive
Talk to an expert