← Xoolink

Xoolink webhooks

Connect Xoolink's public needs and events to Slack, Teams, HubSpot, Notion or your own system.

Choosing the format

Slack and Teams accept their incoming-webhook or workflow URL directly. Language is chosen per destination, and mentions coming from user content are neutralized.

Connecting Slack in two clicks

In the organization's admin space, choose Connect Slack, authorize Xoolink, then pick the channel. Xoolink requests only incoming-webhook access, does not keep the Slack OAuth token, and encrypts the channel's incoming URL. Manual entry remains available.

Available events

Discreet needs, demo needs and needs that might contain an amount are excluded. Internal fields of event hosts are never sent. Tick only the cycles useful to your destination.

No event exists for the internal life of a pack. The revenue split, payments in and out and their confirmations, milestones, documents, positions and prices, pact signatures and an organization's private clauses trigger no delivery and appear in no payload. They are readable by their members only. See the revenue split.

{
  "id": "evt-need-created-req-123-v1",
  "type": "need.created",
  "version": "1",
  "occurred_at": "2026-07-24T16:30:00.000Z",
  "organization_id": null,
  "data": {
    "id": "req-123",
    "title": "Securing a network of clinics",
    "required_expertise": ["Cybersecurity", "Compliance"],
    "remote_allowed": true
  }
}

After a signal, GET /api/v1/opportunities/:id or GET /api/v1/events/:id returns the current public state. A 404 confirms the resource is no longer public.

Verifying the standard format's signature

The X-Xoolink-Signature and X-Xoolink-Delivery-Format headers accompany every delivery. For standard JSON, compute an HMAC SHA-256 over <timestamp>.<raw body> with the secret shown at creation. Compare in constant time and reject timestamps older than five minutes. Slack and Teams authenticate their own URL, so no HMAC secret is shown for those formats. Their sensitive URLs are encrypted and masked in the interface.

Reliability and idempotency

Delivery follows an at-least-once model. A network interruption can happen after your server processes an event but before Xoolink records the acknowledgement, so a later attempt may contain the same event.

Need to read data on demand?

See the public API v1 documentation and the HubSpot and Notion recipes. Bearer API keys and webhook signing secrets are distinct and must never be swapped.

Electronic signature

Yousign uses a native connection, separate from the outgoing webhooks above. Xoolink receives Yousign state changes on a dedicated URL, signed with the secret provided at connection time.