Skip to main content
The Webhooks primitive lets your backend (or a specific tenant’s) subscribe to Naive events. When a matching event fires, Naive POSTs an HMAC-signed, retried payload to your URL. It’s the bridge that makes flows like backlink-outreach autonomous: an inbound reply triggers email.received, your handler resumes the agent.

Events

Naive emits these events today (subscribe to any subset):
The advertised event list always matches what Naive actually emits. GET /v1/webhooks/event-types is the source of truth.

Subscribe

A subscription created on the root client is company-wide (tenant_user_id null, receives events for all tenants); created via forUser(id) it’s scoped to that tenant. The returned secret is shown once — store it to verify signatures.

Verify deliveries

Each POST carries X-Naive-Signature (HMAC-SHA256 of the raw body) and X-Naive-Event. Verify with the helper:
Delivery is best-effort with retry/backoff (3 attempts) and is logged; failures don’t block the originating action.

REST

Per-tenant subscriptions live under /v1/users/:user_id/webhooks. See the Webhooks API reference and the webhooks sub-client.

Billing

Free.