POST with a JSON body, signed with a secret that only you and Coverbase hold, so your receiver can prove the call came from Coverbase before it acts on it.
An endpoint receives events in two ways. It receives every event it is subscribed to on the Webhooks page, and it receives whatever a workflow’s Send webhook step addresses to it. Every attempt either way is recorded in the endpoint’s delivery history.
The mistake people make most often is saving the webhook before the signing secret is stored where the receiver can read it. Coverbase never shows the secret again after you save, so the only fix is to set a new one and update the receiver.
Opening the page
Open Configuration at the bottom of the left navigation and choose Webhooks in the Developers and integrations group, or type “webhook” into Search configurations…. The page opens for the Admin and Member roles only. Only an Admin can add, edit, test or delete an endpoint; a Member sees the list and the delivery history, with Only admins can add, change, test or delete webhooks. where the Add webhook button would be. A person with a custom role does not see the page, whatever the role grants; see Permissions and roles.
The Webhooks page with three endpoints: one subscribed to five events, one that only receives workflow deliveries, and one switched off.
Adding an endpoint
Have the receiver running before you start, and decide on a secret: a random string of at least 16 characters. Coverbase does not generate one for you.Open the form
Enter the endpoint
https://. Coverbase refuses a URL that carries a username or password, uses a non-standard port, or points at a private, loopback, link-local or cloud metadata address. The rules are in URL restrictions.Set the signing secret
Choose the events
Label it
Save

The Add webhook form filled in. The secret is masked, and the eye icon reveals it until you save.
Choosing events
The Events picker lists every event Coverbase emits, by a readable name: Vendor Created is theVendor.Created event, Assessment Updated is Assessment.Updated. Type in the search box to narrow the list, and tick as many as you need. The field then reads 5 selected or similar. What each event carries in its payload is in the event catalog.

The Events picker searched for 'Assessment'. Ticked events are the ones this endpoint receives.
- An Updated event fires on every edit. A webhook subscribed to Vendor Updated receives every change to every vendor, including a typo fix. There is no field filter on a webhook. If your receiver only cares about some changes, leave the event off the webhook and send it from a workflow that names this endpoint in Target webhooks. There, the trigger can watch specific fields and conditions can narrow it further (see Sending events from a workflow).
- One name does not follow the pattern.
WorkflowRun.Createdis listed as Running the workflow. - Monitoring record events are listed only when your workspace uses monitoring records.
Testing an endpoint
Send a test before you rely on an endpoint, and again after you change the receiver or the secret.Open the test dialog
Pick the event type
webhook.test, whose payload is just {"test": true}. Pick a real event type instead to send a sample of that event’s payload. Example payload shows the body your endpoint will receive; the event_id and occurred_at are filled in when the test is sent.Send it

The test dialog with Vendor Updated selected. The envelope is signed exactly like a real delivery.
webhook.test if your receiver cannot tolerate that.
Copy as cURL copies the same test as a command against the test endpoint of the Webhooks API. It expects two environment variables: COVERBASE_API, the API base URL, and COVERBASE_API_KEY, an API key.
Reading delivery history
Click the Delivery history icon on a row, or click the endpoint’s Health value. The dialog lists every recorded attempt for that endpoint, newest first, 50 to a page. Previous and Next move between pages.408, 429 or 5xx status. Coverbase makes up to six attempts, waiting about 4 seconds, 16 seconds, 64 seconds, then 4 minutes twice between them, and records each attempt as its own row with the same event ID. Any other 4xx or 3xx status, a refused URL and a test event are not retried. Each retry is signed again with a new timestamp, so make your receiver idempotent on the event ID: a delivery that succeeded but answered too slowly can arrive twice.
The Status filter at the top narrows the page you are looking at, not the whole history, so page through with Previous and Next when you are hunting for older failures. Coverbase keeps each attempt for 90 days. What each recorded field means, and how to read the same history through the API, is in Webhook delivery history.
Editing, pausing and deleting
Click the Edit icon to open Edit webhook. It is the same form, with the current URL, events, description and status filled in. Click Save changes to apply an edit, and Coverbase confirms with Webhook updated. The next delivery uses the new settings.
Edit webhook. The signing secret field is empty on purpose: leave it blank to keep the current secret.