> ## Documentation Index
> Fetch the complete documentation index at: https://docs.amdital.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Webhooks Setup

> Receive real-time events from AmDital via webhooks. Register endpoints, verify signatures, and handle retries.

## Register a Webhook

Configure webhook endpoints in your workspace settings to receive events.

```bash theme={null}
POST https://api.amdital.com/api/v1/webhooks
{
  "url": "https://example.com/webhooks/amdital",
  "events": ["task.created", "invoice.paid", "ticket.resolved"]
}
```

## CRM Events

CRM object events fire on the corresponding mutation. Deal lifecycle events are granular — a won deal fires `deal.won` (not just `deal.updated`).

```text theme={null}
lead.created | lead.updated | lead.deleted
deal.created | deal.updated | deal.deleted
deal.stage_changed | deal.won | deal.lost

// deal.stage_changed / deal.won / deal.lost payload.data:
{ id, name, fromStage?, toStage?, value, currency, lostReason? }
```

## Signature Verification

Every webhook payload includes an `X-AmDital-Signature` header of the form `sha256=<hex>`. Verify it using your webhook secret with HMAC-SHA256 over the raw request body.

```js theme={null}
const crypto = require('crypto')
const sig = req.headers['x-amdital-signature'] // "sha256=<hex>"
const expected =
  'sha256=' + crypto.createHmac('sha256', WEBHOOK_SECRET).update(rawBody).digest('hex')
if (!crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected))) {
  throw new Error('Invalid signature')
}
```

## Retry Policy

AmDital retries failed deliveries up to 3 times with exponential backoff (\~10s, \~20s). After 3 failures, the event is marked as failed and visible in the webhook logs.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.