Integrations

Webhooks

Send owner alerts, new signups and workflow emails to Zapier, Make, your CRM or your own server.

Available on: Starter or higher (or a trial)

On this page
  1. 1

    Get a URL that accepts webhooks

    For example a Zapier Catch Hook, a Make Custom webhook, or an endpoint on your server. It must start with https://.

  2. 2

    Connect it

    Go to Settings → Integrations → Webhooks, paste the URL, choose the events and click Connect. Atlis creates a signing secret for you.

  3. 3

    Send a test

    Click Send test event. Atlis posts a sample owner alert and shows whether your endpoint answered with a 2xx status.

Events

EventWhenIncludes
Owner alerts (owner_alert)The same moments as the owner alerts: likely to buy, paying customer at risk, likely to cancel, usage dropped or surged. Sent whether or not Slack is on for that alert.alert, label, detail (the reasons), user, profileUrl
New signups (new_signup)A new user is identified by the snippet or the server API. CSV imports don't send it.user with plan and first source, profileUrl
Workflow emails sent (workflow_email)A workflow sends its first email to someone. Follow-up emails don't send it.trigger, user, profileUrl

Each request is a POST with a JSON body like this, and the headers Atlis-Event (the event type) and Atlis-Signature:

Example: owner alert
{
  "id": "5b2f…",
  "createdAt": "2026-10-06T09:30:00.000Z",
  "workspaceId": "YOUR_WORKSPACE_ID",
  "type": "owner_alert",
  "alert": "likely_buyer",
  "label": "Likely to buy",
  "detail": "invited a teammate, visited pricing",
  "user": {
    "id": "u_123",
    "email": "sam@acme.com",
    "name": "Sam"
  },
  "profileUrl": "https://www.theatlis.com/workspace/…/users?userId=u_123"
}

Check the signature

Atlis-Signature looks like t=1760000000,v1=…. v1 is an HMAC-SHA256 of the timestamp, a dot and the raw request body, using your signing secret. Compare it before trusting the request, and ignore requests older than a few minutes. Zapier and Make users can skip this.

Node.js
const crypto = require("crypto");

function isFromAtlis(rawBody, header, secret) {
  const parts = Object.fromEntries(header.split(",").map((p) => p.split("=")));
  const expected = crypto.createHmac("sha256", secret).update(`${parts.t}.${rawBody}`).digest("hex");
  const fresh = Math.abs(Date.now() / 1000 - Number(parts.t)) < 300;
  return fresh && crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(parts.v1 || ""));
}

Good to know

  • The URL must be https and reach a public address. Atlis doesn't follow redirects, so use the final URL.
  • Atlis waits up to 4 seconds for an answer and doesn't retry a failed delivery, so make your endpoint answer quickly.
  • At most 25 events are sent at a time, for example when one hourly run finds many owner alerts.
  • New secret replaces the signing secret right away. Remove stops all webhooks.
  • Sending webhooks costs nothing in Firestore; they're sent from data Atlis already has.

More in Integrations

Try it in your own workspace

Start with a 14-day trial with Growth features. No credit card needed.

Start free