# Set up a project webhook

Add a webhook endpoint in your project's Developer settings, copy its signing secret, send a test, and retry or replay failed deliveries.

A project webhook sends testimonial events from one project to a URL you choose, such as your own server or an automation tool. Webhooks are on Premium and Business, and the workspace owner and the project's Admins can set them up. To send one form's submissions somewhere instead, see [Send a form's submissions to a webhook](/help/integrations/form-webhooks).

1. **Open the Webhooks tab**

   Open the project, click the gear icon next to its name at the bottom of the sidebar, and choose the **Developer** tab. Then click **Webhooks**. (The **Tracking** tab beside it is for Proof Impact.)

   The **Testimonial webhooks** card lists the project's endpoints, with a count of how many you have out of your plan's limit. If your plan doesn't include webhooks, you see **Developer Webhooks** and **Upgrade to unlock** instead.

2. **Add an endpoint**

   Click **Add endpoint** and fill in the form:

   - **Name**: a label for you, such as "CRM sync".
   - **Endpoint URL**: where to send the requests. For an automation tool, such as Zapier, Make or n8n, create its webhook trigger there first and paste the address it gives you. It must be an `https://` address on the public internet. Addresses with a user name or password in them, `localhost`, private network addresses and internal host names (such as ones ending in `.local` or `.internal`) are refused.
   - **Events**: tick the events you want. **testimonial.created** and **testimonial.approved** are ticked to start with. **testimonial.updated** fires often: on edits, tag changes and when a video finishes processing. [Webhooks](/help/integrations/webhooks#events) lists when each event is sent.
   - **Include bulk imports and review sync events**: off to start with. While it's off, this endpoint gets no event when a file import or a review sync (such as Google or G2) brings testimonials in. What you do with one of them later (approve, edit, archive, delete) is always sent. Tick it if you want the arrivals too. A large import then sends a lot of deliveries, which can take hours to all go out.

   Click **Add endpoint**. When you've reached your plan's limit, the button is greyed out and **Endpoint limit reached** says so: delete an endpoint or upgrade to add another.

3. **Copy the signing secret**

   The new endpoint's secret, starting with `whsec_`, appears next to **Signing secret** in its **Delivery log** card, below the list. Click **Copy** and store it in your receiver (or your automation tool) now. It's shown only this once: afterwards the page shows just its first and last characters.

   Your receiver uses it to check each request's `X-Signature` header; see [Webhook signatures, headers and payloads](/help/integrations/verify-webhook-signatures). If you lose it, regenerate it (see below).

4. **Send a test**

   Click **Send test** on the endpoint. If it's subscribed to several events, first pick the one to test in the menu beside the button. ReTestimonial sends a signed request with sample data straight away and shows the result, such as **Test delivered (200)**, or the error your endpoint returned.

   Tests work only while the endpoint is **ACTIVE**, and they don't appear in the delivery log. Their ids start with `test_`, so your receiver can recognize them and skip them.

5. **Check the delivery log**

   Real events start arriving as your testimonials change. Click **Logs** on an endpoint to show its **Delivery log**: each delivery's **Event**, **Status**, number of **Tries**, **HTTP** status code and when it was **Created**, newest first. Choose a status in **Filter** to narrow the list, and click **Refresh Logs** to update it. See [What each delivery status means](#what-each-delivery-status-means).

   Click **View** on a delivery to open **Delivery details**: the full request payload, the URL it went to, the last error, and your endpoint's response headers and body.

## What each delivery status means

| Status         | Meaning                                                                                                                                                 |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **PENDING**    | Waiting to be sent, or to be tried again.                                                                                                               |
| **PROCESSING** | Being sent right now.                                                                                                                                   |
| **SUCCEEDED**  | Your endpoint answered with a 2xx status code.                                                                                                          |
| **FAILED**     | All four attempts failed.                                                                                                                               |
| **CANCELED**   | Stopped before it was sent, for example by a new signing secret, a new URL or the endpoint being disabled. **Cancel reason** in its details says which. |

Successful deliveries stay in the log for 30 days, failed and canceled ones for 90 days.

## Retry or replay failed deliveries

A failed delivery is tried again automatically after 1 minute, 10 minutes and 1 hour. If all four attempts fail, it's marked **FAILED**. Once you've fixed your receiver:

- **One delivery:** click **Retry** on its row. It's there for **FAILED** and **CANCELED** deliveries.
- **Many deliveries:** click **Replay**, whose number is how many failed and canceled deliveries the endpoint has, and confirm with **Replay**. Each replay resends up to 500 of them, oldest first. To resend only some, tick **Use replay filters** first and choose an event, **Older than 24h** or **Older than 7d**.

A retried or replayed delivery goes to the endpoint's current URL, signed with its current secret, and gets four new attempts. It keeps its original `id` and payload, so a receiver that skips ids it has already handled won't process it twice.

You can't retry or replay while the endpoint is **DISABLED** or **SUSPENDED (plan)**. On a **PAUSED** endpoint, the deliveries wait until you activate it.

## Pause, edit or delete an endpoint

Click the three-dot menu on the endpoint:

- **Edit endpoint**: change its name, URL, events or the bulk imports setting, then click **Save changes**. Changing the URL cancels the deliveries still waiting for the old one; replay them to send them to the new URL.
- **Pause deliveries**: events keep queuing but nothing is sent until you choose **Activate endpoint**. A paused endpoint still counts toward your plan's limit.
- **Regenerate signing secret**: see the next section.
- **Delete endpoint**: removes the endpoint and its whole delivery history, after you confirm. This can't be undone.

## Regenerate the signing secret

Do this if the secret may have leaked, or when someone who knew it leaves. Choose **Regenerate signing secret** in the endpoint's menu and confirm with **Regenerate secret**. The new secret is shown once, next to **Signing secret** in the **Delivery log** card: copy it into your receiver straight away.

The old secret stops working at once, and deliveries that were still waiting are canceled. New deliveries your receiver rejects while it still has the old secret are retried as usual. When the receiver has the new secret, click **Replay** to resend the canceled ones.

## If an endpoint is disabled or suspended

- **DISABLED:** after 15 failed attempts in a row, the endpoint turns itself off and cancels the deliveries still waiting. The workspace owner gets an email, the owner and the project's Admins get a notification in the app, and the reason and last error show under the endpoint's status. Fix your receiver, choose **Activate endpoint** in the menu, then click **Replay**.
- **SUSPENDED (plan):** your plan changed. If it no longer includes webhooks, every endpoint is suspended; if it allows fewer endpoints, your oldest ones keep working and the newer ones are suspended. A suspended endpoint keeps its waiting deliveries, and you can't reactivate it yourself: after you upgrade again, it resumes on its own when you next open the **Webhooks** tab, or at the next daily check. On a plan without webhooks, the **Webhooks** tab shows the upgrade card, with your saved endpoints listed under it: you can't edit or send from there, but **Delete endpoint** removes one with its delivery history.

## What happens next

- Build your receiver with [Webhook signatures, headers and payloads](/help/integrations/verify-webhook-signatures): how to check the signature, and what each event contains.
- [Webhooks](/help/integrations/webhooks) explains the events, how delivery works and the plans.
- To change plans, see [Plans and pricing](/help/account/plans-upgrades-and-cancelling).
