Skip to content

Send new responses to your app

Add an endpoint to a form and Reuily will send each new response to your application automatically.

Updated View as Markdown

Quick answer

How do Reuily webhooks deliver form responses?

Reuily sends an HTTPS POST request with a signed JSON event for each new response. Your endpoint has 10 seconds to accept it; retryable failures receive up to five additional delivery attempts.

Timeout

10 seconds

Delivery

At least once

Security

Signed requests

How do I set up a webhook?

  1. Step 1

    Open your form

    Go to Integrations and select the Webhooks tab.
  2. Step 2

    Add the endpoint

    Select Add endpoint, then enter a name and the public HTTPS address that will receive responses.
  3. Step 3

    Copy the signing secret

    Copy the secret shown after saving and store it securely with your application secrets.
  4. Step 4

    Confirm delivery

    Select Send a test and open View activity. A successful response means your endpoint is ready.

What does Reuily send?

For each new response, your endpoint receives a POST request with a JSON body. It includes the form, submission details, and a labelled answer for every response field.

Example event

JSON

{  "id": "evt_4f5f9c...",  "type": "form.submission.created",  "api_version": "2026-07-01",  "created_at": "2026-07-29T12:00:00Z",  "data": {    "form": {      "id": "Ab12Cd34",      "name": "Customer feedback"    },    "submission": {      "id": "Ef56Gh78",      "submitted_at": "2026-07-29T11:59:58Z",      "time_to_complete_ms": 42000,      "answers": [        {          "field": {            "id": "rating-field",            "label": "Rating",            "type": "rating"          },          "value": 5        }      ]    }  }}

How do I verify each request?

Use the request headers and your signing secret to confirm that the request came from Reuily. Verify the exact request body before reading the JSON.

Request headers

Reuily-Event
What happened.
Reuily-Delivery
The unique delivery ID.
Reuily-Timestamp
When the request was signed.
Reuily-Signature
The signature to verify.

Verification example

Choose JavaScript or Python, then use the function before processing the event.

import { createHmac, timingSafeEqual } from "node:crypto"; const secret = process.env.REUILY_WEBHOOK_SECRET; export function verifyWebhook(rawBody, timestamp, signature) {  if (Math.abs(Date.now() / 1000 - Number(timestamp)) > 300) return false;   const match = /^v1=([a-f0-9]{64})$/.exec(signature);  if (!match) return false;   const expected = createHmac("sha256", secret)    .update(timestamp + ".")    .update(rawBody)    .digest();  const received = Buffer.from(match[1], "hex");   return timingSafeEqual(received, expected);}
  • Keep the signing secret in an environment variable or secret manager.
  • Reject requests with timestamps outside your allowed window.
  • Compare signatures using a constant time function.
  • Rotate the secret if it may have been exposed.

Which response should my endpoint return?

Save or queue the event, then respond within 10 seconds. Complete longer work after responding.

Accepted

Return any 2xx status after your app has safely accepted the event.

Try again

Timeouts, connection failures, 408, 409, 425, 429, and 5xx responses cause another attempt.

Retry schedule

Reuily can try five more times: after about 5 minutes, 30 minutes, 1 hour, 6 hours, and 24 hours.

A valid Retry-After header can ask Reuily to wait longer, up to 24 hours.

Reuily does not follow redirects. Other 3xx and 4xx responses stop delivery until you fix the endpoint.

How do I avoid processing an event twice?

The same event can occasionally arrive again if the connection drops after your app accepts it.

  • Save Reuily-Delivery before starting the work created by the event.
  • Skip the event when your app has already processed that delivery ID.
  • Expect responses submitted close together to arrive in a different order.
  • Use the event and submission timestamps when order matters to your workflow.

Where can I check delivery activity?

Open your form, go to Integrations, select Webhooks, and choose View activity on the endpoint you want to inspect.

  • Check whether a response was delivered, is retrying, or needs your attention.
  • Read the safe failure explanation to understand what to check at your destination.
  • After making a fix, select Send a test to confirm the endpoint works.
  • After a longer outage, open the three dot menu and select Add previous responses.

What the activity log includes

Delivery activity shows safe failure explanations and retry information.

Raw response bodies and headers are hidden from every workspace user, including owners and admins, because destination responses may contain private data.

This does not change the submission payload sent to your destination. Limited diagnostics may still be retained internally with delivery history.

Understand delivery errors

Use the status code to choose the first thing to check at your destination.

401 / 403
The destination rejected authentication or access. Check its credentials and permissions.
404
The webhook address was not found. Check the endpoint URL.
429
The destination is rate-limiting requests. Check its request limits.
408 or no response
The destination timed out or could not be reached. Check that it is online and publicly reachable, and accept or queue events promptly.
409 / 425
The destination could not accept the event yet. Check its availability and event handling.
5xx
The destination encountered a server error. Check its service status or server logs.
3xx
The destination returned a redirect. Use the final HTTPS endpoint URL; Reuily does not follow redirects.
Other 4xx
The destination rejected the request. Check its expected payload and endpoint configuration.

When “Retry scheduled” appears

This status appears only while an automatic retry is pending. If automatic attempts are exhausted, fix the destination and then use Send a test, Retry, or Add previous responses as appropriate.

Delivery history is kept for 30 days

Form responses remain stored separately. Delivery activity is operational history.

Common questions

How long does my endpoint have to respond?

Your endpoint has 10 seconds. Save or queue the event, return a 2xx response, and perform longer work afterward.

Which failures does Reuily retry?

Reuily retries timeouts, connection failures, and 408, 409, 425, 429, and 5xx responses. It can make five additional attempts over approximately 24 hours.

Can the same event arrive more than once?

Yes. Delivery is at least once. Store the Reuily-Delivery value and skip IDs your application has already processed.