A source is a representation of a service that sends HTTP requests to the Hookdeck Event Gateway. For example, a third-party service sending webhooks, such as Shopify and Stripe, or an internal service making an HTTP request to distribute an event to other services, external or internal.

How sources work

Each source is given a unique Hookdeck URL that can be pasted into the HTTP or webhook URL field of the sender platform, or used within code when making the HTTP request.

Once HTTP requests are received by Hookdeck via the source URL, events are ingested and routed according to your connection rules.

Hookdeck is a platform for asynchronous messaging and therefore returns a basic customizable synchronous HTTP response to the client that has invoked the source URL. It is not possible to synchronously return a response from a destination to the client (for example, the result of an API call). However, you can use an asynchonous workflow to achieve this and send the result of any work done by a destination via a webhook callback. See the Hookdeck destination response FAQ for more information.

You can customize the source URL to use your own custom domain name. See Custom Domain for more information.

Source Types

Source Types help you quickly configure sources for specific platforms and services. When you select a Source Type, Hookdeck automatically sets up the appropriate configuration including authentication methods, required headers, and response formats commonly used by that platform.

For example, selecting the "Stripe" Source Type will automatically configure the source to handle Stripe's webhook signature verification and respond with the expected 200 status code.

With generic types such as "Webhook" and "HTTP" you can still customize the configuration to match your specific need regardless of the provider is directly supported by Hookdeck.

Source Types include popular platforms like:

158 SOURCES

Every source verifies signatures out of the box. Jump straight to its guide, agent skill, sample payloads, or official docs.

3 3dEYE THREE_D_EYE
A Adyen ADYEN Guide Skill Payloads
A AiPrise AIPRISE Guide Skill Payloads
A Aircall AIRCALL Guide Skill Payloads
A Airtable AIRTABLE Guide Skill
A Airwallex AIRWALLEX Guide Skill Payloads
A Akeneo AKENEO Guide Skill Payloads
A Alchemy ALCHEMY Guide Skill Payloads
A Alipay ALIPAY Guide Skill Payloads
A Asana ASANA Guide Skill
A Ascend ASCEND Guide Skill Payloads
A Ashby ASHBY Guide Skill
A Attentive ATTENTIVE Guide Skill Payloads
A AWS SNS AWS_SNS Guide Skill Payloads
A Azure Event Grid AZURE_EVENT_GRID Guide Skill Payloads
B Baselinker BASELINKER Guide Skill
B BigCommerce BIGCOMMERCE Guide Skill Payloads
B Bondsmith BONDSMITH
B Bridge API BRIDGE_API Guide Skill Payloads
B Bridge XYZ BRIDGE_XYZ Guide Skill Payloads
B Bunny Stream BUNNY_STREAM Guide Skill Payloads
C Chaindots CHAINDOTS
C Chargebee Billing CHARGEBEE_BILLING Guide Skill Payloads
C Circle CIRCLE Guide Skill Payloads
C Claude CLAUDE Guide Skill Payloads
C Cloudinary CLOUDINARY Guide Skill Payloads
C Cloudsignal CLOUDSIGNAL Guide Skill Payloads
C Coinbase COINBASE Guide Skill Payloads
C Commercelayer COMMERCELAYER Guide Skill Payloads
C Community COMMUNITY Guide Skill Payloads
C Courier COURIER Guide Skill Payloads
C Cronofy CRONOFY Guide Skill Payloads
C Cursor CURSOR Guide Skill Payloads
C Customer.io CUSTOMERIO Guide Skill Payloads
D Discord DISCORD Guide Skill Payloads
D DocuSign DOCUSIGN Guide Skill Payloads
E ElevenLabs ELEVENLABS Guide Skill Payloads
E Enode ENODE Guide Skill
E Ethoca ETHOCA Guide Skill
E Exact Online EXACT_ONLINE Guide Skill Payloads
F Facebook FACEBOOK Guide Skill Payloads
F FastSpring FASTSPRING Guide Skill Payloads
F Faundit FAUNDIT Guide Skill Payloads
F Favro FAVRO Guide Skill Payloads
F Fireblocks FIREBLOCKS Guide Skill Payloads
F Fireflies FIREFLIES Guide Skill Payloads
F Fiserv FISERV
F Flexport FLEXPORT Guide Skill Payloads
F Formstack FORMSTACK
F Front FRONTAPP Guide Skill Payloads
F FusionAuth FUSIONAUTH Guide Skill Payloads
G Gemini GEMINI Guide Skill Payloads
G GitHub GITHUB Guide Skill Payloads
G GitLab GITLAB Guide Skill Payloads
G GoCardless GOCARDLESS Guide Skill Payloads
G Google Pub/Sub GOOGLE_PUBSUB Guide Skill
G Green Dot GREENDOT Guide Skill Payloads
H Hookdeck Outpost HOOKDECK_OUTPOST Skill
H HTTP HTTP
H HubSpot HUBSPOT Guide Skill Payloads
I Intercom INTERCOM Guide Skill Payloads
L Linear LINEAR Guide Skill Payloads
L LinkedIn LINKEDIN Guide Skill Payloads
L Lithic LITHIC Guide Skill Payloads
M Mailchimp MAILCHIMP Guide Skill Payloads
M MailerSend MAILERSEND Guide Skill Payloads
M Mailgun MAILGUN Guide Skill Payloads
M Managed MANAGED
M Meraki MERAKI Guide Skill Payloads
M Microsoft Graph MICROSOFT_GRAPH Guide Skill Payloads
M Microsoft SharePoint MICROSOFT_SHAREPOINT Guide Skill
M Monday MONDAY Guide Skill Payloads
N Neon NEON Guide Skill
N Nuvemshop NUVEMSHOP Guide Skill Payloads
N Nylas NYLAS Guide Skill Payloads
O Okta OKTA Guide Skill Payloads
O OpenAI OPENAI Guide Skill Payloads
P Paddle PADDLE Guide Skill Payloads
P Paymob PAYMOB Guide Skill Payloads
P PayPal PAYPAL Guide Skill Payloads
P PayPro Global PAYPRO_GLOBAL Guide Skill
P Paystack PAYSTACK Guide Skill Payloads
P Persona PERSONA Guide Skill Payloads
P Picqer PICQER Guide Skill Payloads
P Pipedrive PIPEDRIVE Guide Skill Payloads
P Polar POLAR Guide Skill Payloads
P Portal PORTAL
P Postmark POSTMARK Guide Skill Payloads
P Praxis PRAXIS Guide Skill Payloads
P Property Finder PROPERTY-FINDER
P Publish Api PUBLISH_API
P Pylon PYLON Guide Skill
Q Quoter QUOTER Guide Skill
R Razorpay RAZORPAY Guide Skill Payloads
R Recharge RECHARGE Guide Skill Payloads
R Recurly RECURLY Guide Skill Payloads
R Repay REPAY
R Replicate REPLICATE Guide Skill
R Resend RESEND Guide Skill Payloads
R Retell RETELL Guide Skill Payloads
R Revolut REVOLUT Guide Skill Payloads
R RingCentral RING_CENTRAL Guide Skill Payloads
S Sanity SANITY Guide Skill
S Scrapfly SCRAPFLY Guide Skill Payloads
S SendGrid SENDGRID Guide Skill Payloads
S ShipBob SHIPBOB Guide Skill
S ShipHero SHIPHERO Guide Skill Payloads
S ShipStation SHIPSTATION Guide Skill Payloads
S Shopify SHOPIFY Guide Skill Payloads
S Shopline SHOPLINE Guide Skill Payloads
S Slack SLACK Guide Skill Payloads
S Smartcar SMARTCAR Guide Skill Payloads
S Smile SMILE Guide Skill Payloads
S Solidgate SOLIDGATE Guide Skill Payloads
S Square SQUARE Guide Skill Payloads
S Statsig STATSIG Guide Skill Payloads
S Strava STRAVA Guide Skill Payloads
S Stripe STRIPE Guide Skill Payloads
S Svix SVIX Guide Skill
S Synctera SYNCTERA Guide Skill
T Tally TALLY Guide Skill Payloads
T Tebex TEBEX Guide Skill Payloads
T Telnyx TELNYX Guide Skill Payloads
T Tikkie TIKKIE Payloads
T TikTok TIKTOK Guide Skill Payloads
T TikTok Shop TIKTOK_SHOP Guide Skill Payloads
T Token.io TOKENIO Guide Skill Payloads
T Treezor TREEZOR Guide Skill Payloads
T Trello TRELLO Guide Skill Payloads
T Twilio TWILIO Guide Skill
T Twitch TWITCH Guide Skill Payloads
T Twitter TWITTER Guide Skill Payloads
T Typeform TYPEFORM Guide Skill Payloads
U Upollo UPOLLO Guide Skill
U Utila UTILA Guide Skill Payloads
V Vercel VERCEL Guide Skill Payloads
V Vercel Log Drains VERCEL_LOG_DRAINS Guide Skill Payloads
V Volume VOLUME Payloads
W Walmart WALMART Guide Skill Payloads
W Webhook WEBHOOK
W WeChat WECHAT Guide Skill Payloads
W WhatsApp WHATSAPP Guide Skill Payloads
W Wix WIX Guide Skill
W WooCommerce WOOCOMMERCE Guide Skill Payloads
W WorkOS WORKOS Guide Skill Payloads
Z Zendesk ZENDESK Guide Skill Payloads
Z Zerohash ZEROHASH Guide Skill Payloads

Content-types

Hookdeck aims to be compatible with every API provider and with common HTTP event payloads. To accomplish this, we remain platform-agnostic and ingest requests (up to 10 MiB) with one of the following content-types:

  • text/plain
  • text/xml
  • application/json
  • application/x-www-form-urlencoded
  • application/xml
  • application/*+json
  • application/jwt
  • application/x-ndjson
  • multipart/form-data

If you encounter a problem integrating a specific API provider, send us a message.

Create a source

Creating a source allows Hookdeck to begin receiving and routing events sent from a specific origin.

  1. Follow the instructions for creating a connection
  2. When configuring the source, select the appropriate Source Type from the dropdown
  3. Configure any additional settings specific to your chosen Source Type
POST
/2025-07-01/sources
Request body example
JSON
{
  "name": "something-else"
}
Response example
JSON
{
  "code": "RESOURCE_ALREADY_EXISTS",
  "status": 409,
  "message": "Resource already exists",
  "data": {
    "id": "src_v5lfi6g0iqsm38",
    "resource_type": "source"
  }
}
curl -X POST "https://api.hookdeck.com/2025-07-01/sources" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "stripe-prod",
    "type": "STRIPE",
    "config": {
      "auth": {
        "webhook_secret_key": "whsec_..."
      }
    }
  }'

Custom methods

POST, PUT, PATCH, and DELETE requests are accepted by default. GET requests are not accepted by default, but you can enable them in the Source Configuration > Advanced Source Configuration section when creating or updating your sources.

HTTP Methods in the advanced configuration section in Source form

You can also enable them explicitly by using a x-hookdeck-allow-methods query string parameter in your Hookdeck source URL.

?x-hookdeck-allow-methods=get

Custom responses

Some API vendors modify their behavior based on the response they receive from a request. For these providers, Hookdeck supports setting custom responses to satisfy their requirements.

Customize Response in Source form

You can also use query string parameter x-hookdeck-response to explicitly customize the response. Append one of the following query parameters to the Hookdeck-provided source URL to achieve the desired response.

ResponseQuery parameter exampleBehavior
Empty?x-hookdeck-response=null or ?x-hookdeck-responseHookdeck responds with an empty body
Text?x-hookdeck-response[text]=Hello+WorldHookdeck responds with the text Hello World
JSON?x-hookdeck-response[json]=%7B%22message%22%3A%22Hello%20World%22%7DHookdeck responds with the specified JSON
XML?x-hookdeck-response[xml]=<root><child></child></root>Hookdeck responds with the specified XML

Add source authentication

Requests can optionally be authenticated. While Source Types come with recommended authentication settings, you can customize these as needed. Hookdeck supports generic authentication options, HMAC, Basic Auth, and API Keys, which cover the majority of authentication providers.

If you've selected a specific Source Type, the authentication method will be pre-configured according to that platform's requirements. You'll only need to provide the necessary credentials.

Configure how incoming requests from a source are authenticated.

Over the API, authentication lives inside the source's config object. Generic types such as HTTP and WEBHOOK take an auth_type naming the scheme, plus an auth object holding its credentials. Platform Source Types such as STRIPE already know their scheme, so they take auth on its own.

  1. Open the Connections page.
  2. Click the source you want to authenticate.
  3. Click Open Source.
  4. Under Advanced Source Configuration, toggle the Source Authentication switch and select the appropriate authentication method from the dropdown.
  5. Enter the information required by the authentication method.
  6. Click Save.
PUT
/2025-07-01/sources/:id
Request body example
JSON
{
  "name": "shopify"
}
Response example
JSON
{
  "id": "src_qa5626p6y5o79b",
  "team_id": "tm_lbhzBKgFOUnB",
  "updated_at": "2026-01-14T13:36:41.934Z",
  "created_at": "2026-01-14T13:35:55.226Z",
  "name": "shopify",
  "description": null,
  "type": "WEBHOOK",
  "config": {
    "allowed_http_methods": [
      "POST",
      "PUT",
      "PATCH",
      "DELETE"
    ],
    "custom_response": null,
    "auth": null,
    "auth_type": null
  },
  "disabled_at": null,
  "url": "http://localhost:8787/qa5626p6y5o79b",
  "authenticated": false
}
curl -X PUT "https://api.hookdeck.com/2025-07-01/sources/src_123456789" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "config": {
      "auth_type": "HMAC",
      "auth": {
        "algorithm": "sha256",
        "encoding": "base64",
        "header_key": "x-webhook-signature",
        "webhook_secret_key": "your_webhook_secret"
      }
    }
  }'

All secrets are AES encrypted.

In the connection's page, your source will now have a shield icon next to it.

Edit source authentication

Edit a source to update the authentication method or change the credentials.

  1. Open the Connections page.
  2. Click the source you want to edit the authentication method for.
  3. Click Open Source.
  4. Scroll to Source Authentication under Advanced Source Configuration, and change the authentication method and related credentials.
  5. Click Save.
PUT
/2025-07-01/sources/:id
Request body example
JSON
{
  "name": "shopify"
}
Response example
JSON
{
  "id": "src_qa5626p6y5o79b",
  "team_id": "tm_lbhzBKgFOUnB",
  "updated_at": "2026-01-14T13:36:41.934Z",
  "created_at": "2026-01-14T13:35:55.226Z",
  "name": "shopify",
  "description": null,
  "type": "WEBHOOK",
  "config": {
    "allowed_http_methods": [
      "POST",
      "PUT",
      "PATCH",
      "DELETE"
    ],
    "custom_response": null,
    "auth": null,
    "auth_type": null
  },
  "disabled_at": null,
  "url": "http://localhost:8787/qa5626p6y5o79b",
  "authenticated": false
}

Remove source authentication

Removing authentication from a source will stop the authentication and verification of any incoming requests and all requests will be accepted.

  1. Open the Connections page.
  2. Click the source you want to remove authentication from.
  3. Click Open Source.
  4. Under Advanced Source Configuration, toggle off the Source Authentication switch.
  5. Click Save.
PUT
/2025-07-01/sources/:id
Request body example
JSON
{
  "name": "shopify"
}
Response example
JSON
{
  "id": "src_qa5626p6y5o79b",
  "team_id": "tm_lbhzBKgFOUnB",
  "updated_at": "2026-01-14T13:36:41.934Z",
  "created_at": "2026-01-14T13:35:55.226Z",
  "name": "shopify",
  "description": null,
  "type": "WEBHOOK",
  "config": {
    "allowed_http_methods": [
      "POST",
      "PUT",
      "PATCH",
      "DELETE"
    ],
    "custom_response": null,
    "auth": null,
    "auth_type": null
  },
  "disabled_at": null,
  "url": "http://localhost:8787/qa5626p6y5o79b",
  "authenticated": false
}

Edit a source

Editing a source lets you change the name of a source in your project.

  1. Open the Connections page.
  2. Click the source you want to edit.
  3. You can edit the source from inside the popup or click Open Source to edit in full page.
  4. Click Save.
PUT
/2025-07-01/sources/:id
Request body example
JSON
{
  "name": "shopify"
}
Response example
JSON
{
  "id": "src_qa5626p6y5o79b",
  "team_id": "tm_lbhzBKgFOUnB",
  "updated_at": "2026-01-14T13:36:41.934Z",
  "created_at": "2026-01-14T13:35:55.226Z",
  "name": "shopify",
  "description": null,
  "type": "WEBHOOK",
  "config": {
    "allowed_http_methods": [
      "POST",
      "PUT",
      "PATCH",
      "DELETE"
    ],
    "custom_response": null,
    "auth": null,
    "auth_type": null
  },
  "disabled_at": null,
  "url": "http://localhost:8787/qa5626p6y5o79b",
  "authenticated": false
}

Once a source has been renamed, its name is updated throughout the project and within any associated connection(s).

Disable a source

Disabling a source temporarily halts inbound requests at the associated Hookdeck URL. An HTTP 200 status code will still be returned for any request received on your Source URL.

This process also disables all the connections that are associated to that source.

  1. Open the Connections page.
  2. Click the source you wish to disable.
  3. Click ••• button in the bottom right corner of the popup.
  4. Click Disable Source.
PUT
/2025-07-01/sources/:id/disable
Response example
JSON
{
  "id": "src_qa5626p6y5o79b",
  "team_id": "tm_lbhzBKgFOUnB",
  "updated_at": "2026-01-14T13:36:41.948Z",
  "created_at": "2026-01-14T13:35:55.226Z",
  "name": "shopify",
  "description": null,
  "type": "WEBHOOK",
  "config": {
    "allowed_http_methods": [
      "POST",
      "PUT",
      "PATCH",
      "DELETE"
    ],
    "custom_response": null
  },
  "disabled_at": "2026-01-14T13:36:41.947Z",
  "url": "http://localhost:8787/qa5626p6y5o79b",
  "authenticated": false
}
curl -X PUT "https://api.hookdeck.com/2025-07-01/sources/src_123456789/disable" \
  -H "Authorization: Bearer YOUR_API_KEY"

Enable a source

Enabling a source returns that source to its previously active state.

  1. Open the Connections page.
  2. Click the disabled source you wish to enable.
  3. Click ••• button in the bottom right corner of the popup.
  4. Click Enable Source.
PUT
/2025-07-01/sources/:id/enable
Response example
JSON
{
  "id": "src_qa5626p6y5o79b",
  "team_id": "tm_lbhzBKgFOUnB",
  "updated_at": "2026-01-14T13:36:41.959Z",
  "created_at": "2026-01-14T13:35:55.226Z",
  "name": "shopify",
  "description": null,
  "type": "WEBHOOK",
  "config": {
    "allowed_http_methods": [
      "POST",
      "PUT",
      "PATCH",
      "DELETE"
    ],
    "custom_response": null
  },
  "disabled_at": null,
  "url": "http://localhost:8787/qa5626p6y5o79b",
  "authenticated": false
}
curl -X PUT "https://api.hookdeck.com/2025-07-01/sources/src_123456789/enable" \
  -H "Authorization: Bearer YOUR_API_KEY"

Hookdeck will resume ingesting requests from the enabled source. You may need to enable the associated connection(s) when the source was disabled or create new connections. Requests received from the source while it was disabled will not be available for replay.

Delete a source

Deleting a source permanently disables inbound requests at the associated Hookdeck URL. Hookdeck will return an HTTP 410 status code for any request received on your Source URL.

Associated event and request data is retained for the remainder of your retention window and will be displayed with a Source Deleted label.

This process also deletes all the connections that rely on the source.

  1. Open the Connections page.
  2. Click the source you wish to delete.
  3. Click ••• button in the bottom right corner of the popup.
  4. Click Delete Source.
  5. Click Delete in the confirmation dialog.
DELETE
/2025-07-01/sources/:id
Response example
JSON
{
  "id": "src_qa5626p6y5o79b"
}
curl -X DELETE "https://api.hookdeck.com/2025-07-01/sources/src_123456789" \
  -H "Authorization: Bearer YOUR_API_KEY"

Once a source has been deleted, it will disappear from your list of sources and the Connections page.