AtlasWork, planned itself.

    The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

    System status
    • SSO
    • SCIM
    • Two-factor sign-in
    • Audit log

    Product

    • Overview
    • PDF tools
    • Diagram tools
    • People & HR
    • Integrations
    • Marketplace
    • Pricing

    Resources

    • Guides
    • Glossary
    • Compare
    • Docs
    • API reference
    • Support
    • Changelog
    • Status

    Company

    • About
    • Careers
    • Press
    • Contact

    Legal & trust

    • Trust center
    • Security
    • Privacy
    • Terms
    • DPA
    • GDPR
    • SLA
    • Refunds
    • Google API data
    Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
    PrivacyTermsSecurityStatus

    You are in control of your cookies

    Atlas uses strictly necessary cookies to keep you signed in. With your consent, we add anonymized product analytics, conversion attribution, and remembered preferences. Change your mind any time at /privacy/cookies.

    Off until you agree · Change it any time

    • Necessaryalways on
    • Analyticsopt-in
    • Marketingopt-in
    • Preferencesopt-in
    Skip to documentation
    Docs
    Back to Atlas

    Start here

    • Overview

    Developer

    • REST API guide
    • Authentication
    • API reference
    • MCP (AI agents)
    • MCP tools reference
    • SDKs
    • Quick actions
    • Changelog

    Webhooks

    • Overview
    • Quickstart
    • Events
    • Payloads and headers
    • Security and signing
    • Delivery and retries
    • Managing via API

    Connect

    • Connectors
    • Integrations

    Product

    • Collaboration and chat
    • Signing in and security
    • Client portal

    Reference

    • Glossary
    • Keyboard shortcuts
    • Module reference

    Webhooks

    Quickstart

    Create a subscription, receive your first event, verify its signature, and go live. This path takes you from zero to a trusted, real-time webhook.

    1. 1

      Create a subscription

      Create a subscription in the Atlas dashboard under Settings, then Webhooks, or call the API directly. Both create the same webhook, from two required fields: url (a public HTTPS endpoint of at most 2,048 characters) and events (1 to 50 event names, each an exact name, a wildcard such as project.*, or *).

      curl -X POST https://api.example.com/v1/webhooks \
        -H "Authorization: Bearer atlas_pat_REPLACE_ME" \
        -H "Content-Type: application/json" \
        -d '{"url":"https://example.com/atlas/webhook","events":["task.completed","project.*"]}'

      The response returns { webhook, secret }. The webhook object holds the webhook details; secret, which starts with whsec_, is the signing key you use to verify every delivery.

      Copy your signing secret now

      The signing secret is shown only once, at creation. It cannot be retrieved later. If you lose it, rotate the secret: Atlas signs with both the old and the new secret for a grace window, so you can switch without missing a delivery.
    2. 2

      Receive the event

      Stand up an endpoint that returns a 2xx response quickly. Atlas waits 15 seconds for an answer, so acknowledge at once and move any heavy work onto a queue of your own rather than doing it inline.

      javascript
      app.post(
        "/atlas/webhook",
        express.raw({ type: "application/json" }),
        (req, res) => {
          // verify first (see Security), then enqueue and respond fast
          res.status(200).send("ok");
        },
      );
    3. 3

      Verify every payload

      Verify the signature before you trust a payload. The Atlas-Signature header reads t=<seconds>,v1=<hex>: compute the HMAC-SHA256 of `${t}.${rawBody}` with your signing secret, compare it with each v1, and refuse a t more than five minutes from your clock. See Security and signing for verification code in five languages.

    4. 4

      Go live

      Send a test delivery from the dashboard, or call POST /v1/webhooks/{id}/test-delivery, which sends a subscription.test event to that webhook alone. Watch it land in the delivery log, confirm your endpoint verified and acknowledged it, then start relying on real events. See Delivery and retries and Events for what happens next.

    Next step: secure your endpoint

    Signature verification is required before you trust any payload. Continue to Security and signing for the full verification and replay-defense guide.

    On this page

    • Create a subscription
    • Receive the event
    • Verify every payload
    • Go live