Developers
Webhooks8 min readUpdated Aug 31, 2026

Zapier / Make.com / n8n Integration Guide

Register webhooks via the API and trigger Zaps or scenarios. Get Slack alerts on offers, auto-log interview notes, or sync new jobs to Notion.

At a glance

What you get
Real-time HTTP callbacks when your pipeline changes, so Zapier, Make.com or n8n can act the moment a job moves or an offer lands.
Plan required
Orbyt Ultra, with a read-write token. External API access is gated to the top tier, so a Free or Pro token returns HTTP 403.
Events
Eleven: job created, updated, deleted and status changed; contact created, updated and deleted; activity created; interview scheduled; offer received; and a manual test event.
Registration
There is no dashboard toggle. You register a webhook by POSTing its URL and event list to the webhooks endpoint with your token.
Signature
An X-Orbyt-Signature header carrying the literal text sha256= followed by the hex HMAC-SHA256 of the raw request body, keyed with your secret.
Response deadline
Five seconds. The request is aborted after that, so acknowledge with a 2xx first and do the work afterwards.
Limits
Ten webhooks per user. Redirects are never followed, and the target URL must resolve to a public address.

Overview

Orbyt's webhook system sends real-time notifications when events happen in your pipeline: new jobs added, status changes, offers received, interviews scheduled, and more. Connect these webhooks to Zapier, Make.com, or n8n to build powerful automations.

Prerequisites

  • Orbyt Ultra plan
  • An Orbyt API key with read-write permissions
  • A Zapier, Make.com, or n8n account

Webhook Events

Orbyt can send webhooks for these events:

EventFires When
job.createdA new job is added to the pipeline
job.updatedJob details are modified
job.deletedA job is removed
job.status_changedJob moves to a new status
contact.createdA new contact is added
contact.updatedContact details are modified
contact.deletedA contact is removed
activity.createdAn activity is logged
interview.scheduledA job moves to interviewing status
offer.receivedA job moves to offer status
webhook.testTest event sent manually

Setting Up with Zapier

Step 1: Create a Zap with Webhook Trigger

  1. Log in to Zapier and click Create Zap
  2. For the trigger, search for Webhooks by Zapier
  3. Select Catch Hook as the trigger event
  4. Zapier gives you a webhook URL like: https://hooks.zapier.com/hooks/catch/123456/abcdef/
  5. Copy this URL

Step 2: Register the Webhook in Orbyt

Use the Orbyt API to register Zapier's webhook URL:

curl -X POST https://www.orbytlabs.ai/api/mcp/webhooks \
  -H "Authorization: Bearer ext_your_token" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://hooks.zapier.com/hooks/catch/123456/abcdef/",
    "events": ["job.status_changed", "offer.received", "interview.scheduled"],
    "secret": "my_signing_secret"
  }'

Step 3: Send a Test Event

curl -X POST https://www.orbytlabs.ai/api/mcp/webhooks/test \
  -H "Authorization: Bearer ext_your_token" \
  -H "Content-Type: application/json" \
  -d '{ "webhookId": "wh_abc123" }'

Go back to Zapier and click Test trigger to confirm the test event was received.

Step 4: Add Actions

Now add actions to your Zap. Popular combinations:

WhenThen
Job status changes to "interviewing"Send Slack message to #job-search channel
Offer receivedSend email to partner/spouse with details
New job addedCreate a card in Notion database
Activity loggedAdd row to Google Sheet for tracking
Interview scheduledCreate Google Calendar event with prep notes

Setting Up with Make.com

Step 1: Create a Scenario

  1. Log in to Make.com and create a new scenario
  2. Add a Webhooks module as the trigger
  3. Select Custom webhook
  4. Make gives you a URL like: https://hook.make.com/abc123xyz

Step 2: Register the Webhook

Same as Zapier, use the API to register the Make webhook URL:

curl -X POST https://www.orbytlabs.ai/api/mcp/webhooks \
  -H "Authorization: Bearer ext_your_token" \
  -H "Content-Type: application/json" \
  -d '{
    "url": "https://hook.make.com/abc123xyz",
    "events": ["job.created", "job.status_changed"],
    "secret": "my_make_secret"
  }'

Step 3: Build Your Flow

Make.com's visual builder lets you:

  • Filter events by type (only act on offer.received)
  • Route to different actions based on job status
  • Transform data before sending to other services
  • Iterate over arrays (e.g., multiple contacts on a job)

Setting Up with n8n

Step 1: Add a Webhook Node

  1. Open your n8n instance
  2. Add a Webhook node as the trigger
  3. Set the HTTP method to POST
  4. Copy the production webhook URL

Step 2: Register and Connect

Register the n8n webhook URL using the same API call pattern above. Then add downstream nodes for your automation logic.

Webhook Payload Format

All webhooks are sent as POST requests with this structure:

{
  "event": "job.status_changed",
  "timestamp": "2026-03-29T14:30:00.000Z",
  "data": {
    "id": "job_abc123",
    "company": "Stripe",
    "title": "Senior Frontend Engineer",
    "status": "interviewing",
    "previousStatus": "applied"
  }
}

Webhook Security

Every webhook you registered with a secret carries three headers:

HeaderValueWhy it matters
X-Orbyt-Signaturesha256= followed by the hex HMACThe prefix is part of the value. Strip it before comparing.
X-Orbyt-TimestampISO 8601, the same value as timestamp in the bodyReject anything older than a few minutes to stop replays.
User-AgentOrbyt-Webhooks/1.0A cheap first filter. Never your only check.

The signature is an HMAC-SHA256 of the raw request body, hex encoded, keyed with the secret you set when you registered the webhook. The header value is that hex digest with a literal sha256= in front of it, the same convention GitHub and Stripe use.

// Node. Compare against the header WITHOUT the prefix.
import { createHmac, timingSafeEqual } from "node:crypto";

function verify(rawBody, header, secret) {
  const expected = createHmac("sha256", secret).update(rawBody).digest("hex");
  const received = String(header).replace(/^sha256=/, "");
  if (received.length !== expected.length) return false;
  return timingSafeEqual(Buffer.from(received), Buffer.from(expected));
}

Two things that will bite you if you skip them. Hash the raw body bytes, not a re-serialized object: JSON.parse then JSON.stringify can reorder keys or change spacing, and the digest will not match. And compare in constant time, because a plain === on a signature leaks the correct value one byte at a time.

Managing Webhooks

# List all registered webhooks
curl https://www.orbytlabs.ai/api/mcp/webhooks \
  -H "Authorization: Bearer ext_your_token"

# Delete a webhook
curl -X DELETE https://www.orbytlabs.ai/api/mcp/webhooks \
  -H "Authorization: Bearer ext_your_token" \
  -H "Content-Type: application/json" \
  -d '{ "webhookId": "wh_abc123" }'

Automation Ideas

AutomationServices
Daily pipeline digest in SlackZapier + Slack (scheduled, uses /pipeline endpoint)
Interview prep packet in NotionMake.com + Notion (triggered by interview.scheduled)
Offer celebration alertZapier + Slack/Email (triggered by offer.received)
Job application log in Google SheetsZapier + Google Sheets (triggered by job.status_changed to "applied")
Stale application remindersn8n + Email (scheduled, uses /suggestions endpoint)
Contact sync to HubSpotMake.com + HubSpot (triggered by contact.created)

Tips

  • Register webhooks for specific events rather than all events to reduce noise
  • Always set a secret when creating webhooks and verify signatures in your automation
  • Use Orbyt's test endpoint to verify your automation works before relying on real data
  • Maximum 10 webhooks per user
  • Your endpoint has 5 seconds to answer. We abort the request at 5 seconds, so if your handler does real work, acknowledge with a 2xx first and process afterwards. Zapier, Make and n8n already do this for you.
  • A redirect is a failure, not a hop. We send with redirect: "manual", so a 301 or 302 from your endpoint is recorded as the answer and never followed. Register the final URL. Stripe and GitHub behave the same way, and the reason is that following a redirect would let an endpoint bounce us to an address our SSRF check never saw.
  • Webhook URLs must resolve to a public address. Every A and AAAA record is checked and the socket is pinned to the validated address, so localhost, 10.x, 192.168.x and link-local targets are refused. Use a tunnel (ngrok, Cloudflare Tunnel) when testing locally.

Common questions

How do I verify an Orbyt webhook signature?

Compute an HMAC-SHA256 of the raw request body, hex encoded, keyed with the secret you set when registering the webhook. The X-Orbyt-Signature header is that digest with the literal text sha256= in front of it, so strip the prefix before you compare. Compare in constant time.

Why does my signature check fail even though the secret is right?

Two causes account for almost all of them. The header value begins with sha256= and that prefix is part of the string, so a raw comparison never matches. And the digest is over the raw body bytes, so parsing the JSON and re-serializing it can reorder keys or change spacing and change the hash.

How long does my endpoint have to respond to an Orbyt webhook?

Five seconds. The request is aborted at that point and the delivery is recorded as failed. If your handler does real work, return a 2xx immediately and process afterwards. Zapier, Make.com and n8n already queue behind their catch URLs, so this only affects custom endpoints.

Does Orbyt follow redirects from a webhook endpoint?

No. Deliveries are sent with redirects disabled, so a 301 or 302 is recorded as your endpoint's answer rather than followed. Register the final URL. GitHub and Stripe behave the same way, because following a redirect would let an endpoint bounce the request to an address the safety check never saw.

What events can an Orbyt webhook subscribe to?

Eleven. Four on jobs: created, updated, deleted, and status changed. Three on contacts: created, updated, and deleted. One on activities: created. Two milestones: interview scheduled and offer received. Plus a test event you can fire by hand while wiring things up.

What does an Orbyt webhook payload look like?

A JSON object with exactly three top-level keys. The event key names what happened, the timestamp key carries an ISO 8601 time that matches the X-Orbyt-Timestamp header, and the data key holds the record. On a status change, data includes both the new status and the previous one.

How many webhooks can I register on one Orbyt account?

Ten. The eleventh registration is refused rather than silently replacing an existing one. If you are close to the limit, subscribe one endpoint to several events instead of registering one endpoint per event, since the payload names the event that fired.

Can I point an Orbyt webhook at localhost for testing?

No. Every A and AAAA record for the hostname is resolved and checked, and the socket is pinned to the validated address, so localhost, private ranges and link-local addresses are refused. Use a tunnel such as ngrok or Cloudflare Tunnel, which gives you a public URL that reaches your machine.

How do I test a webhook before real events fire?

Register the webhook, then POST its id to the webhooks test endpoint. That sends a webhook.test event through the exact delivery path a real event uses, including the signature and timestamp headers, so a passing test means your verification code works and not merely that the URL is reachable.

Other integration guides

Ready to build?

Ship it.