POST request to that URL, the agent runs with the request’s JSON body as its message.
The Webhooks API has two parts:
To run an agent at fixed times instead, use the Scheduler API.
Base URL
Collection endpoints end in a trailing slash, for example
/agent-webhooks/ and /agent-webhooks/pause-bulk/. Include it exactly as shown. Requests without it are redirected, and most HTTP clients drop the body and headers when they follow the redirect.Authentication
The two parts authenticate differently. Agent Webhooks endpoints require your Lyzr API key in thex-api-key header. Webhooks are scoped to the key that created them.
secret_key: send X-Webhook-Signature: sha256=<hex_digest>, where the digest is the HMAC-SHA256 of the raw request body. See Trigger Webhook for code examples.
Typical flow
- Create a webhook with Create Webhook and store the returned
webhook_urlandsecret_key. - Configure the external system to
POSTJSON towebhook_url, signed withsecret_key. - Monitor runs with List Recent Webhook Executions.
- If the secret is ever exposed, rotate it with Regenerate Webhook Secret.