Signed senders are verified
Stripe, GitHub, Shopify, Slack and any sender following the Standard Webhooks specification have their signatures checked.
Give a workflow a webhook address and any app that can send an HTTP request can start it: a form, a store, a payment provider, your own code. Describe what should happen next in plain words; AI builds it, and it runs the same way every time.
The same three steps whatever sends the request.
When the store sends an order, update the sheet and tell the channel. Plain words.
Each webhook trigger has a key, and its address is bound to it, so it survives every edit.
Paste the address into the other app’s webhook settings. Each delivery starts one run.
Checked before your workflow’s first line runs.
Stripe, GitHub, Shopify, Slack and any sender following the Standard Webhooks specification have their signatures checked.
A signed endpoint can accept only the sender event you name, so a workflow never runs on the wrong one.
The workflow can act in any of 1,400+ integrations, or any API with published documentation.
An HTTP request one app sends to an address when something happens, like a new order or a paid invoice. Whenever gives each workflow its own address to receive them.
It does the same first job, catching a request from any app. The difference is what follows: you describe the rest of the workflow instead of adding steps, and a run is billed once however many steps it has.
For Stripe, GitHub, Shopify, Slack and Standard Webhooks senders, yes: the signature is checked before a run starts.
Sources reviewed September 30, 2026.
Describe what should happen when it arrives. Whenever builds it and runs it the same way every time.