Skip to main content
A webhook trigger gives an agent its own endpoint URL. When an external system, such as a ticketing tool, a form, a CI pipeline, or GitHub, sends a POST request to that URL, the agent runs with the request’s JSON body as its message. Requests must be signed with the webhook’s secret key, so only systems that hold the secret can trigger the agent. Use a webhook when the agent should react to an event as it happens. To run an agent at fixed times instead, use the Scheduler.

Setting up a webhook

Open the agent in Agent Builder and open its webhook settings. Once the webhook is created, the Webhook Configuration panel shows its details. Screenshot of the Webhook Configuration panel, showing Status set to Active, the POST Endpoint URL https://scheduler.studio.lyzr.ai/webhook-trigger/ followed by the webhook ID with a copy button, a masked Secret Key with the warning "Copy now. You won't be able to view this again." and a copy button, the Created date, and Regenerate Secret, Pause, and Delete buttons.
The secret key is shown only once. Copy it and store it somewhere safe, such as your secrets manager, before closing the panel. If you lose it, select Regenerate Secret to issue a new one.
Each agent has one webhook.

Calling the webhook

Send a POST request to the endpoint URL with a JSON body and an X-Webhook-Signature header. The signature is sha256= followed by the HMAC-SHA256 of the raw request body, using the secret key.
The endpoint responds with 202 right away and the agent runs in the background. Requests with a missing or incorrect signature are rejected with 401. For Python and Node.js examples, see Trigger Webhook.

Connecting GitHub

GitHub signs its webhook deliveries in the same format, so you can point a GitHub webhook straight at the agent:
  1. In your repository, go to Settings > Webhooks > Add webhook.
  2. Set Payload URL to the endpoint URL.
  3. Set Content type to application/json.
  4. Set Secret to the webhook’s secret key.

Managing the webhook

Monitoring runs

Select Executions in the panel header to see every webhook-triggered run, including whether it succeeded, the payload it received, and the agent’s response or error.

Managing webhooks with the API

You can create, pause, resume, and delete webhooks, regenerate secrets, and read execution logs over REST. See the Agent Webhooks API.