Supported entities
Products, services, solutions, core features, segments, personas, use cases, proof points, reference customers, competitors, alternatives, buying triggers, objections, skills, brand voices, motions, and motion playbooks.motion refers to the motion record. motion_playbook refers to a motion playbook record. Neither subscribes to all nested changes. ICPs, motion ICP cells, deprecated hypotheses, and legacy playbooks are excluded, including from all entity types.
Tracked collection changes notify the collection owner. Separate graph edge changes and maintenance writes that bypass normal entity persistence are not included. Soft deletion emits entity.deleted; restoring an entity emits entity.updated.
Create an endpoint
entityTypes to null for all supported types. Empty action/type lists are rejected. The response contains endpoint and a one-time secret, plus _metadata. Store the secret securely. Listing or updating endpoints does not reveal it.
To update, send the complete configuration plus oId to POST /api/v2/entity-webhook/update. Set enabled: false to pause. Delete with DELETE /api/v2/entity-webhook/delete?oId=whe_example.
Event payload
Notifications are small: fetch the entity using its type and ID for current content. A notification is not a full snapshot of the entity at that moment.entity.created, entity.updated, and entity.deleted. changedFields names stored top-level fields or tracked collections; it is not a nested JSON diff. Revision history is asynchronous and does not cover every change. When an exactly correlated revision is available before the first attempt, the notification includes its revisionId, materiality (none, minor, or material), and materialitySource (deterministic or llm). Otherwise these fields are null. Null means unavailable, not insignificant. Retries preserve the payload for that endpoint.
Verify signatures
Every send uses HMAC-SHA256 with the endpoint secret:
Verify the raw request bytes, before parsing JSON. Check the timestamp against a short tolerance to prevent replay, compare signatures in constant time, and deduplicate by event ID. For example, in Node.js:
POST /api/v2/entity-webhook/rotate-secret with { "oId": "whe_example" }. The new secret is shown once and applies to subsequent attempts immediately. Coordinate rotation with your receiver.
Send a test
Use Send test on a saved endpoint, or:test: true, the first configured action/type (persona for all types), and data.object.oId: "example_entity". Revision metadata is null. Do not try to fetch that example entity. The API responds with status, responseStatus, and error, plus _metadata; HTTP 200 alone does not mean the receiver accepted the test. Check status: "delivered".