POST to the URL on the step. The contact then moves on to the next step, whatever the answer was.
If you are moving from Klaviyo, this works like Klaviyo’s webhook action: a destination URL, headers, and a JSON body. The merge tag syntax is different, so read Merge tags before you copy a body across.
Each contact gets one call. Senderz does not retry a failed call, and the
request times out after 10 seconds. The automation carries on either way.
To send Senderz events to your own system with signatures and retries, use
outbound webhooks instead.
Set up the step
1
Add the step
Drag Webhook from the palette onto the canvas, or add it from the +
on a connector between two steps.
2
Enter the POST URL
Paste the address you want to call. It must start with
https://.3
Add headers
Add one row per header, for example
x-api-key with the API key from your
provider.4
Write a body, or leave it empty
Leave JSON body empty to send the default Senderz payload, or write your
own.
5
Test it
Press Test in the automation editor and run the automation for one
contact. See Test the step.
POST URL
The address must be a publichttps:// address on the default port, so leave any port number out of it.
- Private, local and internal addresses are refused. Senderz checks the address when you save the step, and again right before each call.
- Redirects are not followed. If the server answers with a 3xx status, the call is recorded as Redirected. Enter the final address, not one that redirects to it.
Headers
Headers are key and value rows. For example,x-api-key carries an API key.
Content-Type: application/jsonis sent by default. Add your ownContent-Typerow to override it.- Connection headers such as
Host,Content-Length,ConnectionandTransfer-Encodingare not allowed. - A value must fit on one line, with no Hebrew letters or emoji.
- The step shows how many header rows you can add and how long each value can be.
- Merge tags work in header values.
********. Saving the step again keeps the stored value. To change it, type a new value.
JSON body
Leave the body empty and Senderz sends this default payload:- It must be valid JSON.
- Every merge tag must sit inside double quotes, for example
"{{ email }}". - It can be up to 20,000 characters as written, and must stay under about 100 KB once the tags are filled in.
Merge tags
Merge tags work in header values and in the body.
Add a fallback after a pipe.
{{ firstName|friend }} uses friend when the contact has no first name.
Example: send a WhatsApp template through your provider
This setup sends a WhatsApp template through a messaging provider’s API. The address, template ID and field names below are placeholders. Take the real ones from your provider. POST URL
JSON body
+972501234567.
Test the step
Press Test in the automation editor, choose a contact, and run the test. The automation runs once for that contact.- Webhook steps are called for real, with that contact’s details. If the step sends a message through your provider, that contact receives it, so test with your own contact first.
- Test runs skip waits.
- The test dialog shows what each webhook step got back: the HTTP status, how long the call took, and the start of the response.
Check live calls
Select the Webhook step in the editor to see Recent calls for the last 30 days. It shows how many calls were delivered, and for each recent call:- the result
- the HTTP status
- how long the call took
- whether it was a live call or a test
- the start of the response
Troubleshooting
Rejected with 400, 401 or 403
Rejected with 400, 401 or 403
This usually means the API key is wrong or missing, or the provider does
not accept the body. Read the start of the response under Recent calls
or in the test dialog.
No response
No response
The server did not answer within 10 seconds.
Invalid body
Invalid body
A merge tag is outside quotes, or the JSON is broken. Put every tag inside
double quotes and check the brackets and commas.
Nobody entered the automation
Nobody entered the automation
Check the trigger and the entry settings. With Enter only once, a
contact who already went through the automation cannot enter it again. And
adding someone to a list they are already on does not count as joining
that list. See Flow triggers.
Keep API keys safe
Treat API keys like passwords. Do not paste them into chats or screenshots. If a key was shared, ask your provider for a new one.Related
Flow steps and actions
Every block you can place in an automation.
Flow triggers
What starts an automation, trigger filters and re-entry rules.
Publishing and monitoring
Publish checks, test runs and the per-step reports.
Outbound webhooks
Send Senderz events to your own systems as signed HTTPS deliveries.

