Webhooks

Every feedback event, pushed to your own systems.

Choose the events, point them at an endpoint, and InstantFeedback posts each one as JSON the moment it happens — signed, so your side can check it really came from us.

Webhooks
Events
Six, from request sent to survey completed
Format
JSON over HTTP POST
Signature
HMAC-SHA256 of the body, in the X-IFB-Signature header
Configured
Several webhooks per account; one per campaign
What it does

Built for the developer on the other end.

Signed payloads

Every delivery carries an HMAC-SHA256 signature of the raw body in the X-IFB-Signature header, made with your account's secret. Show, copy or regenerate the secret in the settings page.

The data you actually need

Each event carries the request, its campaign, the contact and the date — plus, depending on the event, the grade, the comment, or every survey question with its answer. Add the campaign's custom fields if you want them.

Several webhooks, one account

Set up as many webhooks as you need, each with its own URL and its own events. Pick a default, and let each campaign use it, choose another, or send nothing.

Retries built in

If your endpoint times out or answers with a temporary error, the delivery is retried automatically at growing intervals, and a Retry-After header is respected.

Test before you rely on it

Send a test delivery from the settings page and get a plain answer back: delivered, timed out, or rejected with the status code.

Every campaign type

SMS, email, mixed, web widget and external campaigns all report, so one endpoint sees feedback from every channel you run.

Events

Six events, from the ask to the last answer.

Subscribe each webhook to exactly the ones it needs. The event name is in every payload, so one endpoint can take them all.

  • Request sent — appeal.send — feedback requests went out.
  • Reminder sent — appeal.reminder — a reminder followed up an unanswered request.
  • Grade received — appeal.grade — the customer rated the experience.
  • Comment received — appeal.comment — they added a comment.
  • Survey started — appeal.survey_start — they opened the follow-up survey.
  • Survey completed — appeal.survey_complete — they finished it; every answer is in the payload.
POST /your-endpoint
Content-Type: application/json
X-IFB-Signature: 3f9a5d…c07e

{
  "event": "appeal.grade",
  "data": [
    {
      "id": 48213,
      "type": "email",
      "campaign": {
        "id": 204,
        "name": "Support follow-up"
      },
      "contact": "dana.whitfield@example.com",
      "date": "2026-09-17T08:15:30+00:00",
      "grade": 5
    }
  ]
}

A grade event, pretty-printed for reading — check the signature against the raw body exactly as received. Request-sent and reminder events batch many requests into one delivery, which is why data is always an array.

Setup

Three steps, then it just runs.

Create a webhook

Give it a name and your endpoint's URL, and tick the events it should receive.

Verify the signature

Copy the account's secret and, on your side, compare X-IFB-Signature with an HMAC-SHA256 of each request body.

Switch it on per campaign

Enable webhooks on the campaigns that should report — with the default webhook or a specific one, with or without custom fields.

Questions

Before you ask.

Is there one secret per webhook?

One per account, shared by all its webhooks. Regenerating it invalidates the old one straight away, so update your endpoint at the same moment.

Can one campaign send to several endpoints?

No — a campaign delivers to one webhook. If several systems need the events, have one endpoint fan them out, or give different campaigns different webhooks.

What counts as a failed delivery?

Timeouts, connection errors, rate limiting (429) and server errors (5xx) are retried automatically at growing intervals. Other error responses are treated as final. Redirects aren't followed, so point the webhook at the final URL.

Can our systems send data in, too?

Yes, through the REST API: create feedback requests, submit grades and comments for externally collected feedback, and read responses back, authenticated with API keys you issue and expire yourself.

Which plan includes it?

Integrations are part of the Business and Enterprise tiers. See pricing for what each tier includes.

Wire it into your own stack.

Tell us what should happen when a customer answers, and we'll walk through the webhook side of it on a call.