POST request with a JSON body each time an event happens.
Availability
Webhooks are available on the Scale plan and above, or with the webhook add-on. See Plans and limits. Without webhook access, the Webhooks tab does not show in Settings.Settings
Each chatbot has three webhook URLs, in Settings > Webhooks. Each URL has its own token. Fill in only the ones you need, then select Save Changes.
These are the only four events. SiteGPT sends no other webhook events.
Request format
Security
- The
X-WEBHOOK-TOKENheader is the only way to check that a request comes from SiteGPT. Set a long random token and reject requests where the header does not match. - SiteGPT does not sign webhook requests. There is no signature header.
- Treat each token as a secret. Anyone who knows your URL and token can send you fake events.
Delivery
- SiteGPT sends each event once. It does not retry a failed delivery.
- SiteGPT does not read your response. A
4xxor5xxstatus is not reported anywhere. - Answer quickly with a
2xxstatus and do slow work after you respond. - To find events that you missed, read conversations and leads with API v2.
Events
ADD_MESSAGE
Sent for every message saved in a conversation: AI answers, visitor messages in a human-handled conversation, replies from your team, and system messages.
Do not treat
question or answer as required. Each one can be null, depending on the message type.
NEW_LEAD_CAPTURE
Sent when the chatbot collects a new lead.dashboardUrlopens the lead in your dashboard.customDataholds the answers to your custom lead form fields, keyed by field name. See Collect leads.capturedAtis an ISO 8601 date and time.
CONVERSATION_ESCALATED
Sent when a conversation is escalated to your team. Each escalation sends this event one time. In rare cases, when SiteGPT must process an escalation again after an internal error, the same event can arrive twice. UsethreadId to detect duplicates.
dashboardUrlopens the conversation in your dashboard.userisnullwhen SiteGPT does not know the visitor yet. When it knows the visitor,userhasid,name,email,phone,verified,createdAt, andupdatedAt.
CONVERSATION_ESCALATED_UPDATED
Sent to the escalation URL when the visitor gives contact details after an escalation. It has the same fields asCONVERSATION_ESCALATED, with user filled in.
Create your ticket on CONVERSATION_ESCALATED. Update it on CONVERSATION_ESCALATED_UPDATED, matched by threadId. Do not treat the update as a new escalation.
HIPAA mode
For chatbots in HIPAA mode, SiteGPT removes conversation content and personal data from webhook bodies:ADD_MESSAGE:questionandanswerarenull, andsourcesis empty.- Escalation events:
userisnull. NEW_LEAD_CAPTURE: the name, email, phone, and custom fields are empty.