Inbound webhooks that check every delivery before it becomes a lead
Inbound webhooks are how ad platforms push new leads into DigiPix Flow the moment someone submits a form, and each one is verified, stored once and processed with retries so a bad minute on either side does not cost you an enquiry. For systems of your own, the lead API does the same job with an API key.
- A signature or key checked on every delivery
- Repeat deliveries recognised, never doubled
- Failed events retried, then replayable
- most retries for an event that fails
- 5
- lead per provider event, however often it arrives
- 1
- deliveries a minute accepted on each workspace webhook URL
- 600
What pushes into DigiPix Flow
- Meta Lead AdsFacebook and Instagram forms, signed by Meta
- Google Ads lead formsYour URL plus a key you choose
- WhatsApp repliesMessages and delivery statuses on your number
- Website form postsSigned with the form's own secret
- Lead APIYour own systems, with an API key
- Audit entryA record of every delivery received
A URL anyone could post to
A webhook address is just a link. If it is pasted into the wrong dashboard or leaks in a screenshot, anyone can send fake leads to it, and a receiver that checks nothing will hand them straight to your sales team.
The same lead, delivered three times
Ad platforms retry when they do not hear back quickly. A receiver that does not recognise a repeat turns one enquiry into three records, and three reps end up calling the same person within the hour.
A failure nobody can see or fix
A lead arrives while something downstream is having a bad minute and the processing fails. With no record of the delivery and no way to run it again, the enquiry simply disappears, and nobody finds out until the buyer complains.
A webhook to the CRM for each lead source that pushes
Meta Lead Ads deliver to DigiPix Flow's own endpoint once you connect with your Meta login, so there is no URL to copy. For Google Ads lead forms, the connector shows your workspace's webhook URL and asks for a key; put the same two on your lead form and every submission is posted straight in. Replies on your connected WhatsApp number arrive by webhook too. IndiaMART is different: its enquiries are collected every five minutes rather than pushed.
- Meta Lead Ads, connected with a Meta login
- Google Ads lead forms, with a URL and a key you choose
- WhatsApp messages and delivery statuses on your number
- IndiaMART collected every five minutes instead
Every delivery proves where it came from
Each receiver checks a delivery before it is accepted. Meta's requests must carry a valid signature made with the app secret. A Google Ads delivery must name your workspace's URL and carry the exact key you set, compared in a way that gives nothing away to someone guessing. A request that fails is refused with an error, and a body that is not valid JSON is turned away rather than stored.
- Meta deliveries checked against their signature
- Google Ads deliveries checked against your key
- Unknown URLs and failed checks refused
- Workspace webhook URLs capped at 600 deliveries a minute
Retries from the sender never become extra leads
Every accepted delivery is stored once, keyed on the sender's own event id, such as Google's lead id. When the same event arrives again because the platform retried, DigiPix Flow answers that it already has it and creates nothing new. The lead that is created then goes through your duplicate checks, so a person who fills in two different forms is flagged for review too.
- Each event stored once per sender and connection
- A repeat delivery answered as a duplicate
- Google's test deliveries accepted for setup checks
- New leads still checked against your existing ones
Processing that tries again before it gives up
A stored event is handed to a background worker, so the sender gets its answer quickly and the slower work happens afterwards. If processing fails for a reason that may pass, it is tried again after one minute, then five, fifteen, thirty and sixty, up to the number of attempts your workspace allows. An event that still fails is set aside as dead-lettered, and one that can never succeed is marked failed at once.
- Answered first, processed in the background
- Retries after 1, 5, 15, 30 and 60 minutes
- Your own limit on attempts, up to five
- Dead-lettered events kept, not discarded
Webhook replay for the events that did not make it
Failed and dead-lettered lead events appear in the Capture hub with a Retry button, and each connector with a webhook has a Replay last event action. A replay asks for a reason, needs the right permission and only runs when your workspace allows replays. Anything that already became a lead cannot be retried, so a replay never creates a second copy.
- Retry failed lead events from the Capture hub
- Replay the last failed event from a connector
- A reason and a permission behind every replay
- Processed events refused, so no second lead
Rotate once, and every inbound URL changes
Your workspace has one inbound signing secret, shown a single time and stored only as a hash. Rotating it from Settings also issues new inbound URLs for every connector that uses one, so a URL that has leaked stops working straight away. Update the Google Ads lead form with its new URL and deliveries resume. Each rotation is written to your audit log, as is every delivery received.
- A workspace secret shown once, kept as a hash
- Rotation re-issues every inbound URL
- Old URLs refused as soon as you rotate
- Rotations and deliveries recorded in the audit log
From a new connector to your first pushed lead, in five steps
- STEP 01
Connect the source
Sign in to Meta, or open the Google Ads lead form connector and set a key.
- STEP 02
Paste the URL
Copy your workspace's webhook URL and key into the lead form's settings.
- STEP 03
Send test data
Press Send test data in Google Ads and watch the connector confirm it arrived.
- STEP 04
Let leads flow
Each delivery is verified, stored once and turned into a lead.
- STEP 05
Recover failures
Retry or replay anything that failed, with a reason on record.
Inbound webhooks vs copying leads by hand
| What it covers | Copying leads from ad dashboards by hand | |
|---|---|---|
| How leads arrive | Downloaded from each dashboard when someone remembers | Posted to DigiPix Flow as each form is submitted |
| Trusting the source | Whatever is in the downloaded file | A signature or key checked on every delivery |
| Repeats | The same lead pasted in twice | Recognised by the sender's event id |
| When processing fails | Nobody knows a lead was missed | Retried, then set aside for replay |
| Recovering a lead | Search the dashboard and hope it is still there | Retry from the Capture hub with one click |
| A leaked link | Nothing to change | Rotate and every inbound URL is replaced |
| Evidence | None | Every delivery and rotation in the audit log |
The routes that feed the same intake
These are the routes that push into DigiPix Flow. Ad platforms use their own receivers; your website and your own systems use signed form posts or the lead API.
Inbound webhook questions, answered
What are inbound webhooks in DigiPix Flow?
They are the receivers that let other platforms push events into your workspace: Meta Lead Ads and Google Ads lead forms post new leads, and your connected WhatsApp number posts replies and delivery statuses. Each receiver checks the delivery, stores it once and processes it in the background.
Can any system post JSON to a DigiPix Flow webhook URL?
No. Each inbound URL belongs to a specific provider and checks that provider's signature or key, so there is no general URL that accepts any body. To send leads from a system of your own, use the lead API with an API key, or post to a website form's signed endpoint.
How is this different from the lead API?
Inbound webhooks receive what a platform such as Meta or Google sends in its own format. The lead API is the door for your own code: you send a lead with a Bearer key and an Idempotency-Key header. Both feed the same intake, with the same duplicate checks and assignment rules.
What happens if Google sends the same lead twice?
Nothing new is created. Google's lead id is stored with the first delivery, and any repeat is answered as a duplicate. Google's test deliveries all share a placeholder id, so they are told apart by their content instead, and you can send test data more than once while setting up.
What if processing fails?
The event is retried after one, five, fifteen, thirty and sixty minutes, up to the attempts your workspace allows. If it still fails it is dead-lettered and kept. Failed lead events show in the Capture hub with a Retry button, and connectors offer Replay last event.
Who can replay a webhook event?
People whose role includes permission to replay webhook events, and only while Allow webhook replay is switched on in Settings. Every replay needs a reason, and only failed or dead-lettered events can be replayed.
Does IndiaMART use a webhook?
No. DigiPix Flow collects IndiaMART enquiries every five minutes using your CRM key, which is as often as IndiaMART allows. Those enquiries then go through the same intake as webhook leads.
What do we do if a webhook URL leaks?
Rotate the inbound signing secret in Settings. That issues new inbound URLs at once and the old ones stop working, so copy the new URL into your Google Ads lead form. The new secret is shown once and recorded in the audit log.
Should we use inbound or outbound webhooks?
They work in opposite directions. Inbound webhooks bring leads and messages into DigiPix Flow. Outbound webhooks send signed events from DigiPix Flow to your endpoint when leads, contacts, companies or deals change.
Something we haven't covered? Talk to an expert
Keep exploring
Visit the blog- INTEGRATIONSLead capture APISend leads from your own systems, with safe retries.See the integration
- INTEGRATIONSCRM public APIAPI clients, scopes and keys for the systems that call you.See the integration
- INTEGRATIONSOutbound webhooksThe other direction: signed events sent to your endpoint.See the integration
- INTEGRATIONSGoogle Ads lead formsSet up the webhook URL and key on your lead form assets.See the integration
- INTEGRATIONSMeta Lead AdsFacebook and Instagram leads, delivered once you connect.See the integration
- PRODUCTLead inboxWhere every delivered lead lands, checked and assigned.See how it works
GUIDECRM Migration Checklist: Move From Spreadsheets or Another CRM Without Losing DataA step-by-step crm migration checklist for moving from spreadsheets or another CRM: audit your data, map every field, clean duplicates, run a test import, then plan the cut-over.Read the guide
GUIDEDuplicate Customer Records: Why the Same Buyer Appears Three Times, and How to Fix It for GoodDuplicate customer records creep in from ad forms, phone calls and old spreadsheets until one buyer has three records and two reps calling. This guide shows where they come from, how to merge them safely and how to stop new ones at the door.Read the guide
Let your ad platforms deliver leads straight to your team
Talk to an expert — bring your Meta and Google Ads lead forms, and see a test lead arrive verified and stored once.
- A real person, not a bot
- Bring your lead forms
- See a test lead arrive





