Outbound Webhooks

Fire signed HTTP webhook callbacks on Payload collection create, update, and delete events, delivered durably through the Jobs Queue.

Community 0 44/wk MIT v0.3.5

Installation

pnpm add payload-plugin-outbound-webhooks

About

Payload has no built-in "POST to a URL on document change" mechanism, so this plugin adds one. It attaches `afterChange` and `afterDelete` hooks to the collections you list in `collections`, and when those hooks fire it enqueues a delivery job in Payload's Jobs Queue. That job POSTs a JSON payload (event, collection, docId, full doc, previousDoc on updates, occurredAt) to every subscribed endpoint URL. Because delivery runs through the Jobs Queue, it is non-blocking and survives process restarts, which makes it a good fit for wiring Payload into Zapier, Make, n8n, a CRM, or any HTTP service. You define which collections and events to watch (create, update, delete), and either hardcode endpoint URLs in the `endpoints` array or let editors manage them from a `webhookEndpoints` admin collection that the plugin adds by default. Endpoints are matched against subscription patterns like `orders.create`, `orders.*`, or `*.delete`, with `*` as a wildcard on either side. A per-collection `filter` function can gate which changes actually fire a webhook, for example only triggering on a transition to `published`. Delivery is at-least-once. Network errors, timeouts, and `5xx`/`408`/`429` responses fail the job so the Jobs Queue retries it up to `maxRetries` times (default 5); other `4xx` responses are treated as permanent and logged but not retried, since the identical request would fail the same way. A circuit-breaker disables an endpoint after `failureThreshold` consecutive failures (default 5, set to 0 to disable), so a dead destination stops burning job retries. Admin-managed endpoints persist a counter on their doc; static endpoints read recent delivery history from the `webhookLogs` collection and self-heal through a half-open probe after a cooldown. The breaker and the retry-skip logic both rely on `enableDeliveryLog` staying on (it is on by default). Endpoints with a `secret` set receive an `X-Webhook-Signature` header formatted as `t=<timestamp>,v1=<hmac-sha256 hex digest>`, signed over the raw body. The plugin exports a `verifyPayloadSignature` helper that checks the signature and rejects replays older than 5 minutes by default via `toleranceSeconds`. Every request also carries `X-Webhook-Event` and `X-Webhook-Id` headers, where the id mirrors a `deliveryId` that stays constant across retries, so receivers should dedupe on it rather than on `(event, docId)`.

Package info

Package name
payload-plugin-outbound-webhooks
Latest version
0.3.5
Unpacked size
58 kB
License
MIT
Weekly downloads
44
Last publish
Sep 20, 2026

Similar plugins

More in Workflow