Send new responses to your app
Add an endpoint to a form and Reuily will send each new response to your application automatically.
Quick answer
How do Reuily webhooks deliver form responses?
TimeoutRequest timeout
10 seconds
DeliveryDelivery
At least once
SecurityAuthentication
Signed requests
How do I set up a webhook?
Step 1
Open your form
Go to Integrations and select the Webhooks tab.Step 2
Add the endpoint
Select Add endpoint, then enter a name and the public HTTPS address that will receive responses.Step 3
Copy the signing secret
Copy the secret shown after saving and store it securely with your application secrets.Step 4
Confirm delivery
Select Send a test and open View activity. A successful response means your endpoint is ready.
What does Reuily send?
For each new response, your endpoint receives a POST request with a JSON body. It includes the form, submission details, and a labelled answer for every response field.
Example event
JSON
{ "id": "evt_4f5f9c...", "type": "form.submission.created", "api_version": "2026-07-01", "created_at": "2026-07-29T12:00:00Z", "data": { "form": { "id": "Ab12Cd34", "name": "Customer feedback" }, "submission": { "id": "Ef56Gh78", "submitted_at": "2026-07-29T11:59:58Z", "time_to_complete_ms": 42000, "answers": [ { "field": { "id": "rating-field", "label": "Rating", "type": "rating" }, "value": 5 } ] } }}How do I verify each request?
Use the request headers and your signing secret to confirm that the request came from Reuily. Verify the exact request body before reading the JSON.
Request headers
Reuily-Event- What happened.
Reuily-Delivery- The unique delivery ID.
Reuily-Timestamp- When the request was signed.
Reuily-Signature- The signature to verify.
Verification example
Choose JavaScript or Python, then use the function before processing the event.
import { createHmac, timingSafeEqual } from "node:crypto"; const secret = process.env.REUILY_WEBHOOK_SECRET; export function verifyWebhook(rawBody, timestamp, signature) { if (Math.abs(Date.now() / 1000 - Number(timestamp)) > 300) return false; const match = /^v1=([a-f0-9]{64})$/.exec(signature); if (!match) return false; const expected = createHmac("sha256", secret) .update(timestamp + ".") .update(rawBody) .digest(); const received = Buffer.from(match[1], "hex"); return timingSafeEqual(received, expected);}import hashlibimport hmacimport osimport time secret = os.environ["REUILY_WEBHOOK_SECRET"].encode() def verify_webhook(raw_body: bytes, timestamp: str, signature: str) -> bool: try: if abs(time.time() - int(timestamp)) > 300: return False except ValueError: return False if not signature.startswith("v1="): return False expected = hmac.new( secret, timestamp.encode() + b"." + raw_body, hashlib.sha256, ).hexdigest() return hmac.compare_digest(signature.removeprefix("v1="), expected)- Keep the signing secret in an environment variable or secret manager.
- Reject requests with timestamps outside your allowed window.
- Compare signatures using a constant time function.
- Rotate the secret if it may have been exposed.
Which response should my endpoint return?
Save or queue the event, then respond within 10 seconds. Complete longer work after responding.
Accepted
Return any 2xx status after your app has safely accepted the event.
Try again
Timeouts, connection failures, 408, 409, 425, 429, and 5xx responses cause another attempt.
Retry schedule
Reuily can try five more times: after about 5 minutes, 30 minutes, 1 hour, 6 hours, and 24 hours.
A valid Retry-After header can ask Reuily to wait longer, up to 24 hours.
Reuily does not follow redirects. Other 3xx and 4xx responses stop delivery until you fix the endpoint.
How do I avoid processing an event twice?
The same event can occasionally arrive again if the connection drops after your app accepts it.
- Save
Reuily-Deliverybefore starting the work created by the event. - Skip the event when your app has already processed that delivery ID.
- Expect responses submitted close together to arrive in a different order.
- Use the event and submission timestamps when order matters to your workflow.
Where can I check delivery activity?
Open your form, go to Integrations, select Webhooks, and choose View activity on the endpoint you want to inspect.
- Check whether a response was delivered, is retrying, or needs your attention.
- Read the safe failure explanation to understand what to check at your destination.
- After making a fix, select Send a test to confirm the endpoint works.
- After a longer outage, open the three dot menu and select Add previous responses.
What the activity log includes
Delivery activity shows safe failure explanations and retry information.
Raw response bodies and headers are hidden from every workspace user, including owners and admins, because destination responses may contain private data.
This does not change the submission payload sent to your destination. Limited diagnostics may still be retained internally with delivery history.
Understand delivery errors
Use the status code to choose the first thing to check at your destination.
- 401 / 403
- The destination rejected authentication or access. Check its credentials and permissions.
- 404
- The webhook address was not found. Check the endpoint URL.
- 429
- The destination is rate-limiting requests. Check its request limits.
- 408 or no response
- The destination timed out or could not be reached. Check that it is online and publicly reachable, and accept or queue events promptly.
- 409 / 425
- The destination could not accept the event yet. Check its availability and event handling.
- 5xx
- The destination encountered a server error. Check its service status or server logs.
- 3xx
- The destination returned a redirect. Use the final HTTPS endpoint URL; Reuily does not follow redirects.
- Other 4xx
- The destination rejected the request. Check its expected payload and endpoint configuration.
When “Retry scheduled” appears
This status appears only while an automatic retry is pending. If automatic attempts are exhausted, fix the destination and then use Send a test, Retry, or Add previous responses as appropriate.
Delivery history is kept for 30 days
Common questions
How long does my endpoint have to respond?
Which failures does Reuily retry?
Can the same event arrive more than once?
Reuily-Delivery value and skip IDs your application has already processed.