Integrations
Webhooks
Send owner alerts, new signups and workflow emails to Zapier, Make, your CRM or your own server.
Available on: Starter or higher (or a trial)
On this page
- 1
Get a URL that accepts webhooks
For example a Zapier Catch Hook, a Make Custom webhook, or an endpoint on your server. It must start with
https://. - 2
Connect it
Go to Settings → Integrations → Webhooks, paste the URL, choose the events and click Connect. Atlis creates a signing secret for you.
- 3
Send a test
Click Send test event. Atlis posts a sample owner alert and shows whether your endpoint answered with a 2xx status.
Events
| Event | When | Includes |
|---|---|---|
Owner alerts (owner_alert) | The same moments as the owner alerts: likely to buy, paying customer at risk, likely to cancel, usage dropped or surged. Sent whether or not Slack is on for that alert. | alert, label, detail (the reasons), user, profileUrl |
New signups (new_signup) | A new user is identified by the snippet or the server API. CSV imports don't send it. | user with plan and first source, profileUrl |
Workflow emails sent (workflow_email) | A workflow sends its first email to someone. Follow-up emails don't send it. | trigger, user, profileUrl |
Each request is a POST with a JSON body like this, and the headers Atlis-Event (the event type) and Atlis-Signature:
{
"id": "5b2f…",
"createdAt": "2026-10-06T09:30:00.000Z",
"workspaceId": "YOUR_WORKSPACE_ID",
"type": "owner_alert",
"alert": "likely_buyer",
"label": "Likely to buy",
"detail": "invited a teammate, visited pricing",
"user": {
"id": "u_123",
"email": "sam@acme.com",
"name": "Sam"
},
"profileUrl": "https://www.theatlis.com/workspace/…/users?userId=u_123"
}Check the signature
Atlis-Signature looks like t=1760000000,v1=…. v1 is an HMAC-SHA256 of the timestamp, a dot and the raw request body, using your signing secret. Compare it before trusting the request, and ignore requests older than a few minutes. Zapier and Make users can skip this.
const crypto = require("crypto");
function isFromAtlis(rawBody, header, secret) {
const parts = Object.fromEntries(header.split(",").map((p) => p.split("=")));
const expected = crypto.createHmac("sha256", secret).update(`${parts.t}.${rawBody}`).digest("hex");
const fresh = Math.abs(Date.now() / 1000 - Number(parts.t)) < 300;
return fresh && crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(parts.v1 || ""));
}Good to know
- The URL must be https and reach a public address. Atlis doesn't follow redirects, so use the final URL.
- Atlis waits up to 4 seconds for an answer and doesn't retry a failed delivery, so make your endpoint answer quickly.
- At most 25 events are sent at a time, for example when one hourly run finds many owner alerts.
- New secret replaces the signing secret right away. Remove stops all webhooks.
- Sending webhooks costs nothing in Firestore; they're sent from data Atlis already has.
More in Integrations
Try it in your own workspace
Start with a 14-day trial with Growth features. No credit card needed.