Outbound Webhooks

Configure an Outbound Webhook URL to post events such as incoming messages from customers, incoming call events, and/or status receipts for your outbound messages

Outbound Webhooks can be used to forward the following events or messages to your applications or systems:

  • Status receipts for the outbound messages sent using Webex Connect (E.g., Submitted, Failed, Delivered, etc. subject to channel specific capabilities.)
  • Incoming calls and messages from customers across channels
  • Incoming call events


URL Endpoint Notifications

  • We only support HTTPs URLs. We make a test call to the configured URL and expect a standard 200 HTTP Response before you can save your configuration. All notifications will be delivered by making POST requests.
  • In case Webex Connect is not able to send a notification because of an unreachable URL, it will retry sending notifications three times each, after 60 seconds. The maximum request timeout for each notification is 10 seconds. The HTTP Responses for which retries are not performed are - 202, 203, 204, 205, 206, 207, 208, 226, 300, 301, 302, 303, 304, 305, 306, 307, 308, 400, 402, 404, 405, 406, 407, 408, 409, 410, 411, 414, 415, 416, 418, 505.


SHA256 and SHA512 support

With the v5.6.0 release we have added support for SHA256 and SHA512 signatures while setting up outbound webhooks. SHA1 signature option that was earlier available is no longer supported and cannot be used for new outbound webhook configurations.



The SHA-1 feature is no longer supported for new configurations. The feature will work as is for the existing configurations.

Configuring Outbound Webhooks at a Service Level

To configure an outbound webhook for a given service on Webex Connect platform, perform the following steps:

  1. Navigate to Assets > Integrations.

Integrations in Assets Menu

  1. Click Add Integration > Outbound Webhook.

Create Outbound Webhook

  1. Enter/select details like Name, Entity, Endpoint Configuration.
    • Name - the name that you want to use for your outbound webhook configuration
    • Entity - the Service to which you want to associate your outbound webhook
    • URL - the URL at which the Webex Connect platform notifies your application of incoming events and messages.
  2. Which Notifications Do You Want To Receive - select the required notification you want to receive for the Outbound Webhook.

Outbound Webhook Configuration



For Email Channel, the events marked with Asterisk are applicable only if 'Email via AWS SES' is the selected route.

  1. Enable Hub Signature (Optional Configuration) - The value of the hub secret is used as the key to creating a signature of the notification data and is sent along with the notification, which can then be verified by the receiving server. The signature is the hexadecimal (40-byte) representation of the signature computed using the HMAC algorithm selected during configuration (E.g., one of SHA256 or SHA 512) as defined in RFC2104. When enabled, you will receive an additional header called x-hub-signature.
  2. Select the Authorization that you would like to apply to this Outbound Webhook Configuration. Please refer to the section on Authorization Configuration below for more information.
  3. When you select a phone number from the Entity drop-down and select Incoming Message, the Forward to SMPP checkbox becomes visible if you don't select Enable Hub Signature. When you select the Forward to SMPP checkbox you also need to select a value from Select ESME Bind ID drop-down list.
  1. Click Save.

Configuring Outbound Webhook at Apps Level

To configure an outbound webhook for a given app on Webex Connect platform, perform the following steps:

  1. Click Add Integration > Outbound Webhook.
  2. Enter Name for your outbound webhook configuration.
  3. Select Entity to which you want to associate your outbound webhook at App level. It must be an In-App app asset.
  1. Select the checkboxes for the notifications you want to receive.
  1. Click Save.

How to use Outbound Webhooks to forward delivery receipts

To receive delivery receipts for your outbound messages:

  1. Select a service from the Entity dropdown
  2. Select the outbound channel for which you want to receive the delivery receipts
  3. Select the receipt types you want the notifications for. Please note that different channels offer different kinds of receipts.
    The below table shows which notifications are available for each channel supported by Webex Connect. By default, none of the notifications are selected. You must explicitly select the required notifications channel-wise.
ChannelApplicable Delivery Status
Trombone Connect
Trombone Releas
In-App Messaging / Live ChatSubmitted
Not verified
Note: Delivered, Not verified, Invalid, Bounced, Complaint, Read, and Clicked events are only available if Email via AWS SES is the selected route.
Apple Messages for BusinessSubmitted
Google Business MessagesSubmitted

Sample Payloads for Outbound Message Status and Incoming Messages


Sample Payloads

For Information related to the sample payloads, refer to the section Outbound Webhooks in the API Reference documentation. Please note that the payloads vary for each message type, each event type, and each channel. Also, enhancements are made to these payloads overtime as new message types or events are added and/or existing ones are updated or deprecated. Please keep your application at the receiving end flexible to avoid any impact when such changes are made.

Error Codes


Error Codes

For Information related to the common and channel-specific error codes, refer to the section Channel Specific Status Codes in the API Reference documentation.

Adding Authorization for Outbound Webhook Notifications


Please note that feature is not working for SMS and Voice channels due to a bug that has been fixed in v6.4.1. v6.4.1 is currently live only on Webex Connect Ireland and Canada instances. For other sites, please wait for v6.4.1 to be deployed before using this feature for these two channels.

To add a new authorization, follow the below steps:

  1. Navigate to Assets → Integrations.
  2. Click Add Authorization.
  3. Enter a name for the authorization.
  4. Select the Type of authorization and configure the details. You must configure the following parameters based on the authorization type:
    1. No Auth – select this type when you do not need an authorization
    2. Basic Auth – select this type when you need to do an authorization using username and password
Username/PasswordLogin credentials that you want to use for authentication.
Parameter valueThis is applicable if the parameter is static. Provide value.

c. Digest Auth - select this option when you need to validate the user identity before sending any sensitive information like online banking transactional details. In this type of authorization, a network server receives the request from a user and then sends it to a domain controller. The domain controller responds with a special session key.

UsernameUsername to authenticate the request
RealmString from the server within the www-Authenticate response header
PasswordThe password to authenticate the request
NonceUnique string from the server within the www-Authenticate response header
AlgorithmString that indicates a pair of algorithms used to produce the digest and a checksum
QOPThe quality of protection applied to the message. The value must be one of the alternatives specified by the server in the www-Authenticate response header.
Nonce CountThe hexadecimal count of the number of requests (including the current request) that the client has sent with the nonce value in this request.You must specify the count only if a QOP directive is sent in the www-Authenticate response header.
Client NonceAn opaque quoted string value provided by the client. This value is used by both client and server to avoid chosen plaintext attacks, provide mutual authentication, and message integrity protection.You must specify the count only if a QOP directive is sent in the www-Authenticate response header.
OpaqueA string specified by the server in the www-Authenticate response header. Use this string as is with URLs in the same protection space. Webex Connect recommends that this string be base64 encoded data.

d. AWS Signature - select this option when you want to use the Amazon Work Services workflow for authorization. You must use a custom HTTP scheme based on a keyed-HMAC (Hash Message Authentication Code) for authentication.

Access_KeyUnique access key for an account used to send the request.
Secret_KeyThe unique secret key for an account used to send the request.
RegionThe region that receives the request.
Service_NameService that receives the request.

e. API Key - Enter the Key and Key Value.

f. OAuth 2.0 – is a well-adopted delegated authorization framework. Supports two different grant types for OAuth 2.0.

  1. Authorization code - server issues the token in the context of a user.
  2. Client credentials - grant type is used to obtain an access token outside of the context of a user.
Consumer IDUnique identifier of the consumer obtained during the registration process
Grant TypeType of authentication - Authorization Code or Client Credentials. Its selection depends on the grant type offered by the API.
Client ID (Client Credentials only)Unique identifier of the client obtained from the platform through which the authorization is done.
Client Secret (Client Credentials only)The unique secret of the client obtained from the platform through which the authorization is done.
Consumer ID (Authorization Code only)Unique identifier of the consumer obtained during the registration process.
Consumer Secret (Authorization Code only)The unique secret of the consumer obtained during the registration process.
Call Back URL (Authorization Code only)Webex Connect callback URL will be used during the registration process at the authorization provider’s end. Note: The callback URL is not accessible from a web browser. You need to test it using the custom node only.
Authorization URL (Authorization Code only)Endpoint for authorization server, which retrieves the authorization code must be provided by the authorization provider.
ScopeScope of the access request (multiple space-separated values). This is optional.
Access Token URLEndpoint for the resource server, which exchanges the authorization code for an access token
Access token has a limited validitySpecifies if the token has a limited validity and must be provided by the authorization provider.
ValidityValidity of the token.
Refresh URL TokenIt should be provided by the authorization provider.

It ensures smooth functioning of authorization in the case provided access token has limited validity.
Advance SettingsToggle button that allows you to enable or disable advanced settings.
Access Token URL MethodAn additional method for the access token.
Access Token URL Parameter typeType of access token URL parameter – Body or URL.
Access Token URL HeadersAdditional URL header parameters for the access token
Get Access TokenButton to retrieve the access token
Access TokenDisplays the refresh token
Refresh TokenDisplays the refresh token
Client AuthenticationValue of Client Authentication is defined by the authorization provider’s API.

Send client credentials in body is selected by default.
ValidityThe validity of the token
  1. Click Save.
    The created authorization will be displayed in the list of authorizations which you can associate with the desired Outbound Webhook configuration.