> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lyzr.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Trigger Webhook

> Run an agent from an external system with a signed request.

This is the URL returned as `webhook_url` when you [create a webhook](/enterprise/api/webhooks/agent-webhooks/create). It does not use an API key. Instead, every request must carry an HMAC-SHA256 signature of the raw request body, computed with the webhook's `secret_key`:

```text theme={null}
X-Webhook-Signature: sha256=<hex_digest>
```

Requests with a missing, malformed, or invalid signature are rejected with `401`.

Sign the exact bytes you send. If you serialize the JSON once to sign it and again to send it, whitespace or key-order differences will make the signature fail.

<CodeGroup>
  ```bash cURL theme={null}
  BODY='{"ticket_id":48213,"subject":"Refund not received","priority":"high"}'
  SIG=$(printf '%s' "$BODY" | openssl dgst -sha256 -hmac "$WEBHOOK_SECRET" | sed 's/^.* //')

  curl -X POST "https://scheduler.studio.lyzr.ai/webhook-trigger/$WEBHOOK_ID" \
    -H "Content-Type: application/json" \
    -H "X-Webhook-Signature: sha256=$SIG" \
    -d "$BODY"
  ```

  ```python Python theme={null}
  import hashlib
  import hmac
  import json

  import requests

  webhook_id = "YOUR_WEBHOOK_ID"
  secret = "YOUR_WEBHOOK_SECRET"

  body = json.dumps({"ticket_id": 48213, "subject": "Refund not received", "priority": "high"}).encode()
  signature = hmac.new(secret.encode(), body, hashlib.sha256).hexdigest()

  response = requests.post(
      f"https://scheduler.studio.lyzr.ai/webhook-trigger/{webhook_id}",
      data=body,
      headers={
          "Content-Type": "application/json",
          "X-Webhook-Signature": f"sha256={signature}",
      },
  )
  print(response.status_code, response.json())
  ```

  ```javascript Node.js theme={null}
  import crypto from "node:crypto";

  const webhookId = "YOUR_WEBHOOK_ID";
  const secret = "YOUR_WEBHOOK_SECRET";

  const body = JSON.stringify({ ticket_id: 48213, subject: "Refund not received", priority: "high" });
  const signature = crypto.createHmac("sha256", secret).update(body).digest("hex");

  const response = await fetch(`https://scheduler.studio.lyzr.ai/webhook-trigger/${webhookId}`, {
    method: "POST",
    headers: {
      "Content-Type": "application/json",
      "X-Webhook-Signature": `sha256=${signature}`,
    },
    body,
  });
  console.log(response.status, await response.json());
  ```
</CodeGroup>

## GitHub webhooks

GitHub signs deliveries with `X-Hub-Signature-256`, which uses the same `sha256=<hex_digest>` format. The endpoint accepts it as an alias, so you can point a GitHub webhook straight at `webhook_url`:

1. In your repository, go to **Settings > Webhooks > Add webhook**.
2. Set **Payload URL** to the `webhook_url`.
3. Set **Content type** to `application/json`.
4. Set **Secret** to the webhook's `secret_key`.

## What happens next

The endpoint returns `202` as soon as the request is accepted. The agent runs in the background with the JSON body as its message. Use the `session_id` from the response to find the run in [Get Webhook Execution Logs](/enterprise/api/webhooks/agent-webhooks/logs) or [List Recent Webhook Executions](/enterprise/api/webhooks/agent-webhooks/recent-executions).


## OpenAPI

````yaml openapi/scheduler.yaml POST /webhook-trigger/{webhook_id}
openapi: 3.0.3
info:
  title: Lyzr Scheduler and Webhooks API
  version: 1.1.0
  description: >-
    Scheduler service for running Lyzr agents on cron schedules, triggering
    agents from external systems through signed webhooks, and calling arbitrary
    HTTP endpoints on a cron schedule.
servers:
  - url: https://scheduler.studio.lyzr.ai
security:
  - ApiKeyAuth: []
tags:
  - name: Schedules
    description: Run an agent on a cron schedule.
  - name: Agent Webhooks
    description: Create and manage webhook URLs that trigger an agent.
  - name: Webhook Trigger
    description: Public endpoint external services call to trigger an agent.
  - name: HTTP Schedules
    description: Call any HTTP endpoint on a cron schedule.
paths:
  /webhook-trigger/{webhook_id}:
    post:
      tags:
        - Webhook Trigger
      summary: Trigger webhook
      description: Run an agent from an external system with a signed request.
      parameters:
        - $ref: '#/components/parameters/WebhookId'
        - name: X-Webhook-Signature
          in: header
          required: false
          description: >-
            `sha256=` followed by the hex HMAC-SHA256 of the raw request body,
            keyed with the webhook's `secret_key`. Required unless you send
            `X-Hub-Signature-256`.
          schema:
            type: string
            example: >-
              sha256=5d41402abc4b2a76b9719d911017c592ae2f7c1d7c3c6f0d8e2b1a4f3c9e8d7b
        - name: X-Hub-Signature-256
          in: header
          required: false
          description: >-
            GitHub-style alias for `X-Webhook-Signature`. Same format and same
            signature.
          schema:
            type: string
      requestBody:
        required: true
        description: Any JSON payload. It is forwarded to the agent as the message.
        content:
          application/json:
            schema:
              type: object
              additionalProperties: true
            example:
              ticket_id: 48213
              subject: Refund not received
              priority: high
      responses:
        '202':
          description: The trigger was accepted and the agent is running in the background.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WebhookTriggerResponse'
        '401':
          description: >-
            The signature header is missing, malformed, or does not match the
            body.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: No webhook exists with this ID.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                detail: Webhook not found
        '422':
          $ref: '#/components/responses/ValidationError'
      security: []
components:
  parameters:
    WebhookId:
      name: webhook_id
      in: path
      required: true
      description: ID of the webhook.
      schema:
        type: string
        example: 66f1c3b7e4b0a1b2c3d4e5f7
  schemas:
    WebhookTriggerResponse:
      type: object
      required:
        - message
        - webhook_id
        - agent_id
        - session_id
      properties:
        message:
          type: string
          description: Confirmation message.
        webhook_id:
          type: string
          example: 66f1c3b7e4b0a1b2c3d4e5f7
        agent_id:
          type: string
          example: 66e9b0f2a1c3d4e5f6a7b8c9
        session_id:
          type: string
          description: >-
            Agent session ID for this run. Use it to look up the result in the
            webhook's execution logs.
    Error:
      type: object
      properties:
        detail:
          type: string
          example: Schedule not found
    HTTPValidationError:
      type: object
      properties:
        detail:
          type: array
          items:
            type: object
            properties:
              loc:
                type: array
                description: Path to the invalid field.
                items:
                  oneOf:
                    - type: string
                    - type: integer
              msg:
                type: string
                description: Human-readable error message.
              type:
                type: string
                description: Error type identifier.
  responses:
    ValidationError:
      description: The request failed validation. The body lists each invalid field.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/HTTPValidationError'
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: Lyzr API key. Required on every endpoint except Trigger Webhook.

````