
Zapier / Make.com / n8n Integration Guide
Register webhooks via the API and trigger Zaps or scenarios. Get Slack alerts on offers, auto-log interview notes, or sync new jobs to Notion.
At a glance
- What you get
- Real-time HTTP callbacks when your pipeline changes, so Zapier, Make.com or n8n can act the moment a job moves or an offer lands.
- Plan required
- Orbyt Ultra, with a read-write token. External API access is gated to the top tier, so a Free or Pro token returns HTTP 403.
- Events
- Eleven: job created, updated, deleted and status changed; contact created, updated and deleted; activity created; interview scheduled; offer received; and a manual test event.
- Registration
- There is no dashboard toggle. You register a webhook by POSTing its URL and event list to the webhooks endpoint with your token.
- Signature
- An X-Orbyt-Signature header carrying the literal text sha256= followed by the hex HMAC-SHA256 of the raw request body, keyed with your secret.
- Response deadline
- Five seconds. The request is aborted after that, so acknowledge with a 2xx first and do the work afterwards.
- Limits
- Ten webhooks per user. Redirects are never followed, and the target URL must resolve to a public address.
Overview
Orbyt's webhook system sends real-time notifications when events happen in your pipeline: new jobs added, status changes, offers received, interviews scheduled, and more. Connect these webhooks to Zapier, Make.com, or n8n to build powerful automations.
Prerequisites
- Orbyt Ultra plan
- An Orbyt API key with read-write permissions
- A Zapier, Make.com, or n8n account
Webhook Events
Orbyt can send webhooks for these events:
| Event | Fires When |
|---|---|
job.created | A new job is added to the pipeline |
job.updated | Job details are modified |
job.deleted | A job is removed |
job.status_changed | Job moves to a new status |
contact.created | A new contact is added |
contact.updated | Contact details are modified |
contact.deleted | A contact is removed |
activity.created | An activity is logged |
interview.scheduled | A job moves to interviewing status |
offer.received | A job moves to offer status |
webhook.test | Test event sent manually |
Setting Up with Zapier
Step 1: Create a Zap with Webhook Trigger
- Log in to Zapier and click Create Zap
- For the trigger, search for Webhooks by Zapier
- Select Catch Hook as the trigger event
- Zapier gives you a webhook URL like:
https://hooks.zapier.com/hooks/catch/123456/abcdef/ - Copy this URL
Step 2: Register the Webhook in Orbyt
Use the Orbyt API to register Zapier's webhook URL:
curl -X POST https://www.orbytlabs.ai/api/mcp/webhooks \
-H "Authorization: Bearer ext_your_token" \
-H "Content-Type: application/json" \
-d '{
"url": "https://hooks.zapier.com/hooks/catch/123456/abcdef/",
"events": ["job.status_changed", "offer.received", "interview.scheduled"],
"secret": "my_signing_secret"
}'
Step 3: Send a Test Event
curl -X POST https://www.orbytlabs.ai/api/mcp/webhooks/test \
-H "Authorization: Bearer ext_your_token" \
-H "Content-Type: application/json" \
-d '{ "webhookId": "wh_abc123" }'
Go back to Zapier and click Test trigger to confirm the test event was received.
Step 4: Add Actions
Now add actions to your Zap. Popular combinations:
| When | Then |
|---|---|
| Job status changes to "interviewing" | Send Slack message to #job-search channel |
| Offer received | Send email to partner/spouse with details |
| New job added | Create a card in Notion database |
| Activity logged | Add row to Google Sheet for tracking |
| Interview scheduled | Create Google Calendar event with prep notes |
Setting Up with Make.com
Step 1: Create a Scenario
- Log in to Make.com and create a new scenario
- Add a Webhooks module as the trigger
- Select Custom webhook
- Make gives you a URL like:
https://hook.make.com/abc123xyz
Step 2: Register the Webhook
Same as Zapier, use the API to register the Make webhook URL:
curl -X POST https://www.orbytlabs.ai/api/mcp/webhooks \
-H "Authorization: Bearer ext_your_token" \
-H "Content-Type: application/json" \
-d '{
"url": "https://hook.make.com/abc123xyz",
"events": ["job.created", "job.status_changed"],
"secret": "my_make_secret"
}'
Step 3: Build Your Flow
Make.com's visual builder lets you:
- Filter events by type (only act on
offer.received) - Route to different actions based on job status
- Transform data before sending to other services
- Iterate over arrays (e.g., multiple contacts on a job)
Setting Up with n8n
Step 1: Add a Webhook Node
- Open your n8n instance
- Add a Webhook node as the trigger
- Set the HTTP method to POST
- Copy the production webhook URL
Step 2: Register and Connect
Register the n8n webhook URL using the same API call pattern above. Then add downstream nodes for your automation logic.
Webhook Payload Format
All webhooks are sent as POST requests with this structure:
{
"event": "job.status_changed",
"timestamp": "2026-03-29T14:30:00.000Z",
"data": {
"id": "job_abc123",
"company": "Stripe",
"title": "Senior Frontend Engineer",
"status": "interviewing",
"previousStatus": "applied"
}
}
Webhook Security
Every webhook you registered with a secret carries three headers:
| Header | Value | Why it matters |
|---|---|---|
X-Orbyt-Signature | sha256= followed by the hex HMAC | The prefix is part of the value. Strip it before comparing. |
X-Orbyt-Timestamp | ISO 8601, the same value as timestamp in the body | Reject anything older than a few minutes to stop replays. |
User-Agent | Orbyt-Webhooks/1.0 | A cheap first filter. Never your only check. |
The signature is an HMAC-SHA256 of the raw request body, hex encoded, keyed with the secret you set when you registered the webhook. The header value is that hex digest with a literal sha256= in front of it, the same convention GitHub and Stripe use.
// Node. Compare against the header WITHOUT the prefix.
import { createHmac, timingSafeEqual } from "node:crypto";
function verify(rawBody, header, secret) {
const expected = createHmac("sha256", secret).update(rawBody).digest("hex");
const received = String(header).replace(/^sha256=/, "");
if (received.length !== expected.length) return false;
return timingSafeEqual(Buffer.from(received), Buffer.from(expected));
}
Two things that will bite you if you skip them. Hash the raw body bytes, not a re-serialized object: JSON.parse then JSON.stringify can reorder keys or change spacing, and the digest will not match. And compare in constant time, because a plain === on a signature leaks the correct value one byte at a time.
Managing Webhooks
# List all registered webhooks
curl https://www.orbytlabs.ai/api/mcp/webhooks \
-H "Authorization: Bearer ext_your_token"
# Delete a webhook
curl -X DELETE https://www.orbytlabs.ai/api/mcp/webhooks \
-H "Authorization: Bearer ext_your_token" \
-H "Content-Type: application/json" \
-d '{ "webhookId": "wh_abc123" }'
Automation Ideas
| Automation | Services |
|---|---|
| Daily pipeline digest in Slack | Zapier + Slack (scheduled, uses /pipeline endpoint) |
| Interview prep packet in Notion | Make.com + Notion (triggered by interview.scheduled) |
| Offer celebration alert | Zapier + Slack/Email (triggered by offer.received) |
| Job application log in Google Sheets | Zapier + Google Sheets (triggered by job.status_changed to "applied") |
| Stale application reminders | n8n + Email (scheduled, uses /suggestions endpoint) |
| Contact sync to HubSpot | Make.com + HubSpot (triggered by contact.created) |
Tips
- Register webhooks for specific events rather than all events to reduce noise
- Always set a
secretwhen creating webhooks and verify signatures in your automation - Use Orbyt's test endpoint to verify your automation works before relying on real data
- Maximum 10 webhooks per user
- Your endpoint has 5 seconds to answer. We abort the request at 5 seconds, so if your handler does real work, acknowledge with a 2xx first and process afterwards. Zapier, Make and n8n already do this for you.
- A redirect is a failure, not a hop. We send with
redirect: "manual", so a 301 or 302 from your endpoint is recorded as the answer and never followed. Register the final URL. Stripe and GitHub behave the same way, and the reason is that following a redirect would let an endpoint bounce us to an address our SSRF check never saw. - Webhook URLs must resolve to a public address. Every A and AAAA record is checked and the socket is pinned to the validated address, so
localhost,10.x,192.168.xand link-local targets are refused. Use a tunnel (ngrok, Cloudflare Tunnel) when testing locally.
Common questions
How do I verify an Orbyt webhook signature?
Compute an HMAC-SHA256 of the raw request body, hex encoded, keyed with the secret you set when registering the webhook. The X-Orbyt-Signature header is that digest with the literal text sha256= in front of it, so strip the prefix before you compare. Compare in constant time.
Why does my signature check fail even though the secret is right?
Two causes account for almost all of them. The header value begins with sha256= and that prefix is part of the string, so a raw comparison never matches. And the digest is over the raw body bytes, so parsing the JSON and re-serializing it can reorder keys or change spacing and change the hash.
How long does my endpoint have to respond to an Orbyt webhook?
Five seconds. The request is aborted at that point and the delivery is recorded as failed. If your handler does real work, return a 2xx immediately and process afterwards. Zapier, Make.com and n8n already queue behind their catch URLs, so this only affects custom endpoints.
Does Orbyt follow redirects from a webhook endpoint?
No. Deliveries are sent with redirects disabled, so a 301 or 302 is recorded as your endpoint's answer rather than followed. Register the final URL. GitHub and Stripe behave the same way, because following a redirect would let an endpoint bounce the request to an address the safety check never saw.
What events can an Orbyt webhook subscribe to?
Eleven. Four on jobs: created, updated, deleted, and status changed. Three on contacts: created, updated, and deleted. One on activities: created. Two milestones: interview scheduled and offer received. Plus a test event you can fire by hand while wiring things up.
What does an Orbyt webhook payload look like?
A JSON object with exactly three top-level keys. The event key names what happened, the timestamp key carries an ISO 8601 time that matches the X-Orbyt-Timestamp header, and the data key holds the record. On a status change, data includes both the new status and the previous one.
How many webhooks can I register on one Orbyt account?
Ten. The eleventh registration is refused rather than silently replacing an existing one. If you are close to the limit, subscribe one endpoint to several events instead of registering one endpoint per event, since the payload names the event that fired.
Can I point an Orbyt webhook at localhost for testing?
No. Every A and AAAA record for the hostname is resolved and checked, and the socket is pinned to the validated address, so localhost, private ranges and link-local addresses are refused. Use a tunnel such as ngrok or Cloudflare Tunnel, which gives you a public URL that reaches your machine.
How do I test a webhook before real events fire?
Register the webhook, then POST its id to the webhooks test endpoint. That sends a webhook.test event through the exact delivery path a real event uses, including the signature and timestamp headers, so a passing test means your verification code works and not merely that the URL is reachable.



