Chapter: Webhooks

Integrations

Webhooks

Some providers report events immediately instead of waiting for the next sync. For that, you enter a webhook URL from VentionDesk with them. Every URL belongs to exactly one connection of your workspace.

Where to find the URL

Operations › Sources, on the connection “Show webhook URL” (owner only). The API returns the same URL under GET /v1/integrations/:id/webhook. It stays the same even if you reconnect the connection.

ProviderURLCheck
Stripehttps://api.ventiondesk.com/webhooks/stripe/<workspace>signature in the Stripe-Signature header
Sentryhttps://api.ventiondesk.com/webhooks/errors/sentry/<connection>signature in the Sentry-Hook-Signature header
Bugsnaghttps://api.ventiondesk.com/webhooks/errors/bugsnag/<connection>/<secret>secret in the URL
Rollbarhttps://api.ventiondesk.com/webhooks/errors/rollbar/<connection>/<secret>secret in the URL

VentionDesk fills in the placeholders in angle brackets — always copy the URL from “Show webhook URL” and don’t assemble it yourself.

Stripe

Create it under Stripe › Developers › Webhooks › “Add endpoint” with exactly these events:

  • checkout.session.completed
  • checkout.session.async_payment_succeeded
  • checkout.session.async_payment_failed
  • charge.refunded

Then copy the endpoint’s signing secret (whsec_…) and save the Stripe connection in VentionDesk again with it. Only then does the payment link appear in the invoice email and document — without the webhook a payment would arrive without VentionDesk booking it.

VentionDesk checks the signature (HMAC-SHA256 over timestamp and body) with this secret and only accepts messages whose timestamp deviates by at most five minutes. Events from the other mode than your key (test instead of live or vice versa) are accepted and skipped. Payments from VentionDesk payment links and refunds are booked. The full guide: Connect Stripe.

Sentry

In the internal integration under “Webhooks”, tick “issue” and enter the URL as “Webhook URL”. You enter the integration’s client secret in VentionDesk; VentionDesk uses it to check the Sentry-Hook-Signature signature (HMAC-SHA256 over the body). New and reopened errors then appear immediately. Guide: Connect Sentry.

Bugsnag

In the project under Project settings › “Integrations and email” › “Webhook”, enter it and choose “New errors”, “Frequently occurring errors” and “Reopened errors”. Bugsnag does not sign; the secret is therefore in the URL and is compared. Guide: Connect Bugsnag.

Rollbar

In the project under Settings › Notifications › “Webhook”, enter it and activate “New Item”, “Reactivated Item”, “Resolved Item” and “10^nth Occurrence”. As with Bugsnag, the secret is in the URL. Guide: Connect Rollbar.

From the error trackers VentionDesk only takes metadata — ID, shortened title, level, status, counter, first and last occurrence and the link. Stack traces, event bodies, user data and IP addresses stay with the provider, even if they come along in the webhook.

GitHub

For GitHub you enter nothing: the VentionDesk app delivers pushes, pull requests, check runs and deployment status automatically as soon as it is installed. See Connect GitHub.

How VentionDesk responds

  • Every delivery counts once. A repeated delivery with the same ID is recognised and not processed twice.
  • Wrong signature or wrong secret: the delivery is rejected.
  • If VentionDesk cannot store a delivery, it answers with an error instead of 200 — the provider then delivers again, and nothing gets lost silently.
  • Per IP address, every webhook route accepts up to 600 deliveries per minute.
Webhooks | VentionDesk Docs