Xoolink webhooks
Connect Xoolink's public needs and events to Slack, Teams, HubSpot, Notion or your own system.
Choosing the format
- Standard JSON — the full Xoolink envelope, for HubSpot, Notion, Zapier, Make or your server.
- Slack — a ready-to-read Block Kit message with summary, expertise and a button.
- Microsoft Teams — a ready-to-read adaptive card.
Slack and Teams accept their incoming-webhook or workflow URL directly. Language is chosen per destination, and mentions coming from user content are neutralized.
Connecting Slack in two clicks
In the organization's admin space, choose Connect Slack, authorize Xoolink, then pick the channel. Xoolink requests only incoming-webhook access, does not keep the Slack OAuth token, and encrypts the channel's incoming URL. Manual entry remains available.
Available events
need.created— a public need is published.need.updated— its public content or criteria change.need.withdrawn— it is withdrawn or becomes private; only its identifier, withdrawal date and link are sent.event.created— a public event is created.event.updated— its date, location or public content changes.event.cancelled— it is cancelled; only its identifier, cancellation date and link are sent.
Discreet needs, demo needs and needs that might contain an amount are excluded. Internal fields of event hosts are never sent. Tick only the cycles useful to your destination.
No event exists for the internal life of a pack. The revenue split, payments in and out and their confirmations, milestones, documents, positions and prices, pact signatures and an organization's private clauses trigger no delivery and appear in no payload. They are readable by their members only. See the revenue split.
{
"id": "evt-need-created-req-123-v1",
"type": "need.created",
"version": "1",
"occurred_at": "2026-07-24T16:30:00.000Z",
"organization_id": null,
"data": {
"id": "req-123",
"title": "Securing a network of clinics",
"required_expertise": ["Cybersecurity", "Compliance"],
"remote_allowed": true
}
}
After a signal, GET /api/v1/opportunities/:id or GET /api/v1/events/:id returns the current public state. A 404 confirms the resource is no longer public.
Verifying the standard format's signature
The X-Xoolink-Signature and X-Xoolink-Delivery-Format headers accompany every delivery. For standard JSON, compute an HMAC SHA-256 over <timestamp>.<raw body> with the secret shown at creation. Compare in constant time and reject timestamps older than five minutes. Slack and Teams authenticate their own URL, so no HMAC secret is shown for those formats. Their sensitive URLs are encrypted and masked in the interface.
Reliability and idempotency
Delivery follows an at-least-once model. A network interruption can happen after your server processes an event but before Xoolink records the acknowledgement, so a later attempt may contain the same event.
- Deduplicate durably on
X-Xoolink-Event-IdorIdempotency-Key; both contain the same stable identifier on every attempt. - Store that identifier under a unique constraint, in the same transaction as your business effect, then return
2xx. - Answer within 8 seconds.
- Xoolink makes up to 8 attempts with exponential backoff.
- Base allows 1 destination and keeps 12 deliveries; Alpha allows 2 and keeps 25; Clan allows 10, keeps 100 and adds manual replay.
Need to read data on demand?
See the public API v1 documentation and the HubSpot and Notion recipes. Bearer API keys and webhook signing secrets are distinct and must never be swapped.
Electronic signature
Yousign uses a native connection, separate from the outgoing webhooks above. Xoolink receives Yousign state changes on a dedicated URL, signed with the secret provided at connection time.